# IP Intelligence Briefing: 34.219.67.199/32
## Executive Summary
IP address 34.219.67.199 is a low-risk CloudCompute endpoint operated by Amazon Web Services (AWS) in the US West region. The IP demonstrates standard cloud infrastructure characteristics with a risk score of 25/100 and no active threat indicators. This is a legitimate AWS EC2 instance serving web traffic.
## Risk Assessment
- Risk Score: 25 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Reputation Status: Low Risk
The IP exhibits no malicious behavior indicators and is classified as a basic operator profile.
## Ownership & Infrastructure
- ASN: 16509 (Amazon Technologies Inc.)
- Organization: Amazon Technologies Inc.
- Netname: AT-88-Z
- CIDR Block: 34.192.0.0/10
- RIR: ARIN
- Infrastructure Type: CloudCompute
- Network Role: AWS EC2 Web Server
The endpoint is hosted on Amazon's US West-2 (Oregon) region infrastructure.
## Geolocation
- Country: United States (US)
- Region: Oregon (OR)
- City: Portland
- Coordinates: 45.59°N, 122.6°W
- Timezone: America/Los_Angeles
- Geo Consensus: Validated across multiple sources
## Network Services & DNS
- Open Ports: 443/TCP (HTTPS)
- PTR Hostname: ec2-34-219-67-199.us-west-2.compute.amazonaws.com
- Forward Resolution: Confirmed
- TLS Certificate: Issued by Amazon RSA 2048 M04
- Server Fingerprint: Citrix-3.2.5.9
- Status Code: 200
DNS records are properly configured with SPF and DMARC authentication for the amazonaws.com domain.
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None detected
- Threat Feeds: Empty
## Neighborhood Analysis (34.219.67.0/24)
- Abuse Density: 0
- Classification: Mostly Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
The /24 subnet shows minimal abuse activity with a low inherited risk profile of 2.
## Control Plane & Routing
- Origin ASN: 16509
- BGP Prefix: 34.208.0.0/12
- Route Stability: Moderate (1 route change in 30 days)
- DNSSEC: Valid
- DNSBL Listed: 1 of 8 lists
## Historical Observations
Analysis of 26 observation records indicates stable cloud infrastructure characteristics:
- Cloud Classification: Consistently identified as AWS cloud infrastructure
- Geolocation: Consistent Portland, OR location
- Server Type: Persistent Citrix-3.2.5.9 fingerprint
- Status: No significant behavioral changes observed
## Recommended Actions
No immediate security actions required. The IP presents as legitimate AWS cloud infrastructure. If this endpoint is not expected in your environment, monitor for any behavioral changes that deviate from standard AWS patterns.
## Conclusion
This IP is a legitimate AWS EC2 instance with no observable malicious activity. The low risk score, clean reputation, and standard cloud infrastructure characteristics indicate this is benign hosting infrastructure. SOC analysts may monitor but no blocking or mitigation actions are recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 34.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-34-219-67-199.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-34-219-67-199.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Citrix-3.2.5.9 |
| HTTP Title | β |
π TLS Certificate
| SANs | *.g.us-west-2.rdn.amazonaws.com |
| Valid From | 2026-03-18T00:00:00+00:00 |
| Valid Until | 2026-10-01T23:59:59+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 197 days |
| Serial Number | 025B2E2B21B9F2D4D6DCE6D4C8FC67F4 |
| Thumbprint | 7E75F3936D5D39014412ECEA3C88D773311EAEBF |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 32% | 2 | 3 |
| services | 32% | 2 | 3 |
| ownership | 34% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 31% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 14:53:11 UTC |
| Last Seen | 2026-08-12 19:45:10 UTC |
| Profile Built | 2026-08-12 20:13:17 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 31 |
Full dossier details are available via our API.