IPDebrief

34.244.58.147

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Subject: Intelligence Briefing: 34.244.58.147

Summary: Analysis of IP 34.244.58.147 identified a low-risk endpoint associated with Amazon Web Services infrastructure. While flagged as a "Suspicious Host," the endpoint demonstrated no active attacker behavior or known campaign correlation.

Ownership and Location: The address was attributed to Amazon Data Services Ireland Limited (AS16509, AMAZON-DUB). Reverse DNS resolution confirmed an EC2 instance within the eu-west-1 region (London, GB).

Network Services: Port scanning detected open TCP ports 80, 443, and 8080. Server banners returned "Apache/2.4.18 (Ubuntu)." TLS certificates were issued by Let's Encrypt for the hostname motd.ubuntu.com.

Threat Assessment: The risk score was 25, classified as Low Risk. One DNSBL listing was detected, though specific threat feeds returned no matches. Behavioral data showed zero enumeration strikes, zero total incidents, and zero honeypot hits. The threat actor classification remained generic ("Suspicious Host") without specific campaign correlation.

Recommendation: The recommended action was to monitor the address due to the generic threat indicator, despite the clean neighborhood classification and low severity rating.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡ช Ireland
RegionD
CityDublin
TimezoneEurope/Dublin
Latitude53.35
Longitude-6.26

๐Ÿข Ownership & Registration

OrganizationAmazon Data Services Ireland Limited
ASNAS16509
Network NameAMAZON-DUB
CIDR Block34.240.0.0/13
RIRARIN
CountryIreland
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRec2-34-244-58-147.eu-west-1.compute.amazonaws.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesec2-34-244-58-147.eu-west-1.compute.amazonaws.com

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPF4/4 domains
DMARC4/4 domains
FCrDNSVerified
DNSSECNot signed
CAANot configured
Domains Checked4 domains

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
8080http-alttcpโ€”
Closed Ports22, 25, 3389, 8443 (3 open / 7 scanned)
ServerApache/2.4.18 (Ubuntu)
HTTP Titleโ€”

๐Ÿ” TLS Certificate

An expired certificate for CN=motd.ubuntu.com was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
๐Ÿ”’
CN=motd.ubuntu.com
Issued by CN=YR1, O=Let's Encrypt, C=US
Self-signed: No
SANsmotd.ubuntu.com
Valid From2026-06-21T08:13:33+00:00
Valid Until2026-09-19T08:13:32+00:00 (expired)
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number05A26169F5F4EEAB7AC4CEE4CD1B1106607F
Thumbprint8639D3D41F10421BAA8CA715F4C06886AE7852E0

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
37%
26
routing
13%
11
services
42%
26
ownership
27%
24
reputation
22%
14
geolocation
43%
25
Overall31%1026
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, IE

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-09-02 02:57:12 UTC
Last Seen2026-09-23 14:13:17 UTC
Profile Built2026-09-23 14:25:23 UTC
Data FreshnessLive
Signal Types26
Total Observations45
๐Ÿ” 26 signal types ยท 45 observations collected
This report is generated from 26+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.