IP INTELLIGENCE BRIEFING: 34.235.127.228
Classification: LOW RISK / CLOUD INFRASTRUCTURE
Date: [Current Date]
Analyst: SOC Intelligence
---
1. EXECUTIVE SUMMARY
IP address 34.235.127.228 is identified as a legitimate Amazon Web Services (AWS) cloud infrastructure endpoint. The IP exhibits low risk characteristics with no active threat indicators. The address resolves to EC2 compute instance hostname (ec2-34-235-127-228.compute-1.amazonaws.com) within the AT-88-Z network block. No malicious activity or anomalous behavior was observed during analysis.
---
2. OWNERSHIP AND INFRASTRUCTURE
| Attribute | Value |
|---|---|
| Organization | Amazon Technologies Inc. |
| ASN | 14618 |
| CIDR Block | 34.192.0.0/10 |
| Network | AT-88-Z |
| Location | Ashburn, Virginia, US |
| Provider Score | 0/100 |
| Authority Score | 0/100 |
| Risk Score | 25/100 |
The IP is classified as cloud infrastructure (AWS EC2 instance) with forward DNS resolution confirmed. Service scan results indicate firewalled/no services exposed (no open ports detected).
---
3. THREAT ASSESSMENT
Current Threat Indicators:
- Abuse Confidence Score: Not applicable (no malicious signals)
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Blacklist Count: 1 (of 8 total DNSBLs)
- Known Campaigns: None detected
- Threat Feeds: Empty
Network Neighborhood (34.235.127.0/24):
- Subnet Classification: Clean
- Abuse Density: 0/100
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
---
4. HISTORICAL OBSERVATION ANALYSIS
The IP has generated 25 historical observations. Signal analysis reveals consistent infrastructure patterns:
- Routing signals consistently identified as AWS cloud infrastructure (confidence: 0.85)
- Geolocation signals consistently resolved to Ashburn, VA, US (confidence: 0.56)
- DNSSEC valid with CAAs configured
- Ownership stability: No changes observed
The temporal data indicates no threat persistence (threat observation count: 0) and no persistent malicious behavior.
---
5. RELATIONSHIP MAPPING
The IP maintains DNS associations with the following hostname:
- ec2-34-235-127-228.compute-1.amazonaws.com
Multiple relationship entries confirm network association with AT-88-Z (same network block). No external organizational or certificate relationships beyond AWS infrastructure were detected.
---
6. RECOMMENDED ACTIONS
Based on the low-risk cloud infrastructure profile, the following actions are recommended:
- Firewall Rules: No blocking required. Standard cloud egress/ingress policies apply.
- Monitoring: Continue standard monitoring for this IP range as part of AWS infrastructure baseline.
- Allow List: Consider adding to allow list if this IP is associated with legitimate AWS service endpoints in your environment.
- No Blocking Action: The IP does not warrant blocking or rate-limiting.
---
7. CONCLUSION
IP 34.235.127.228 represents a standard AWS EC2 infrastructure endpoint with no malicious indicators. The IP demonstrates clean neighborhood characteristics and consistent historical behavior. No defensive action is required beyond standard cloud infrastructure monitoring practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS14618 |
| Network Name | AT-88-Z |
| CIDR Block | 34.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-34-235-127-228.compute-1.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-34-235-127-228.compute-1.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 33% | 2 | 4 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 04:59:10 UTC |
| Last Seen | 2026-08-13 00:27:44 UTC |
| Profile Built | 2026-08-13 00:39:13 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.