IPDebrief

34.247.92.68

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 34.247.92.68/32

Date: Current Analysis

Classification: Cloud Infrastructure - Clean

---

## EXECUTIVE SUMMARY

IP 34.247.92.68 is a legitimate Amazon Web Services (AWS) EC2 instance hosted in Dublin, Ireland (eu-west-1 region). The address demonstrates no malicious activity indicators and exhibits consistent clean classification across observation history. Risk assessment yields a moderate score of 50/100, primarily reflecting cloud infrastructure classification rather than malicious behavior.

---

## OWNERSHIP & GEOLOCATION

AttributeValue
**Organization**Amazon Data Services Ireland Limited
**ASN**16509 (AMAZON-AS)
**CIDR Block**34.240.0.0/13
**Network Name**AMAZON-DUB
**Geolocation**Dublin, Leinster, Ireland (IE)
**Infrastructure Type**Cloud Compute (EC2)
**Service Purpose**Firewalled / No Services

The IP resolves to hostname `ec2-34-247-92-68.eu-west-1.compute.amazonaws.com`, confirming AWS infrastructure identity.

---

## THREAT ASSESSMENT

Risk Score: 50 (Moderate)

Abuse Confidence: Not applicable (cloud infrastructure)

Blacklist Count: 0

DNSBL Listed: 2 of 8 total lists

Known Attacker Status: False

Tor Exit Node: False

No threat indicators detected in the current profile. The IP is not associated with known campaigns, spam sources, or malicious actors.

---

## NETWORK CHARACTERISTICS

Open Ports: None detected

Services: None (firewalled)

TLS Certificate: Not applicable

DNS Forward Confirmed: Yes (1 PTR record)

Email Authentication: SPF record present; DMARC present

The absence of open ports indicates proper security hardening typical of AWS EC2 instances.

---

## OBSERVATION HISTORY (20 SIGNALS)

DateSignal TypeConfidenceClassification
2026-08-06Operator Score0.60Basic
2026-08-06Full Profile0.27Standard
2026-07-31Network Scan0.30Clean
2026-07-31Subnet Analysis0.40Clean
2026-07-31Port Scan0.70No Services

Historical data demonstrates consistent clean classification with no escalation in threat signals over the observation period. No evidence of persistent malicious activity.

---

## RELATIONSHIP GRAPH

Total Relationships: 15

Primary Associations:

All relationships point to legitimate AWS infrastructure. No external malicious associations detected.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 34.247.92.68/24

Abuse Density: 0 (Clean)

Total Siblings: 1

Active Siblings: 1

Threat Siblings: 0

The /24 subnet shows no abuse activity. No neighboring IPs flagged as threats.

---

## SECURITY ACTIONS & RECOMMENDATIONS

Risk Assessment: Moderate (50/100)

Recommended Action: Monitor or Block (context-dependent)

Firewall Rules

SystemRule
**iptables**`iptables -A INPUT -s 34.247.92.68 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 34.247.92.68 drop`
**nginx**`deny 34.247.92.68;`
**pfSense**`34.247.92.68/32`
**Cloudflare WAF**Block IP with filter expression `ip.src eq 34.247.92.68`
**AWS WAF**`Addresses: ["34.247.92.68/32"]`

Note: These rules are probabilistic and should be combined with other threat intelligence signals before implementation. Given the IP's AWS infrastructure status and clean threat profile, blocking may be unnecessary unless specific campaign correlation exists.

---

## INTELLIGENCE NARRATIVE

IP 34.247.92.68 represents standard AWS cloud infrastructure with no evidence of malicious activity. The IP's moderate risk score (50) reflects cloud service classification rather than threat behavior. Multiple observations confirm consistent clean status across the /24 subnet. No open services indicate proper security configuration. The IP is associated with legitimate AWS hostname resolution and shows no relationships to known threat actors or malicious campaigns.

SOC Analyst Guidance: Treat as benign traffic unless additional threat intelligence indicates otherwise. No immediate blocking action recommended. Monitor for changes in behavior patterns or unexpected traffic anomalies.

---

Report Generated: IPDebrief Intelligence Platform

Data Sources: Full profile, observation history, relationship graph, neighborhood analysis

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡ช Ireland
RegionD
CityDublin
TimezoneEurope/Dublin
Latitude53.35
Longitude-6.26

๐Ÿข Ownership & Registration

OrganizationAmazon Data Services Ireland Limited
ASNAS16509
Network NameAMAZON-DUB
CIDR Block34.240.0.0/13
RIRARIN
CountryIreland
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRec2-34-247-92-68.eu-west-1.compute.amazonaws.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesec2-34-247-92-68.eu-west-1.compute.amazonaws.com

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
42%
25
routing
13%
11
services
19%
22
ownership
30%
23
reputation
28%
13
geolocation
33%
24
Overall27%1018
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-30 17:12:06 UTC
Last Seen2026-08-13 00:58:44 UTC
Profile Built2026-08-13 01:07:20 UTC
Data FreshnessLive
Signal Types22
Total Observations23
๐Ÿ” 22 signal types ยท 23 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.