The IP address 34.216.137.127 was associated with Amazon Technologies Inc. (ASN 16509), resolving to `ec2-34-216-137-127.us-west-2.compute.amazonaws.com`. Risk assessment placed the asset at a low risk score of 25, though behavioral analysis flagged it as a Suspicious Host with one DNSBL listing.
Data inconsistencies were present regarding geographic origin and identity. Geo-location sources indicated Portland, Oregon, US, whereas the TLS certificate subject claimed affiliation with Samsung Electronics Co., Ltd. in South Korea. The endpoint operated an nginx web server on port 443 with no specific threat indicators or campaign matches.
Due to the presence of signal contradictions and the suspicious host classification, the recommended action was to monitor the IP.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 34.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-34-216-137-127.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-34-216-137-127.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | β |
π TLS Certificate
| SANs | *.file.samsungcloud.comfile.samsungcloud.com |
| Valid From | 2026-03-13T00:00:00+00:00 |
| Valid Until | 2026-09-27T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 00D862EF9A69695BA0FD60DD8B46DE2609 |
| Thumbprint | 910A849CEA7A2DC002CCE864262EA79C21646FD8 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-09-16 05:43:19 UTC |
| Last Seen | 2026-09-16 05:43:19 UTC |
| Profile Built | 2026-09-16 06:00:34 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.