# IP Intelligence Briefing: 35.77.156.228/32
Date: 2026-06-18
Classification: LOW RISK
Risk Score: 25/100
## Executive Summary
IP address 35.77.156.228 is a legitimate Amazon Web Services (AWS) cloud compute instance located in Tokyo, Japan. No active threat indicators were identified. The IP shows standard cloud infrastructure behavior with no evidence of malicious activity.
## Technical Profile
Ownership & Registration:
- Organization: Amazon Data Services Japan
- ASN: 16509
- RIR: ARIN
- Network: AMAZON-NRT (AWS Tokyo Region)
- Registration Type: Cloud Infrastructure
Geolocation:
- Country: Japan (JP)
- City: Tokyo
- Region: 13
- Coordinates: 35.68°N, 139.69°E
- Timezone: Asia/Tokyo
- GeoValidation: Plausible (ICMP probe blocked)
Network Classification:
- Infrastructure Type: CloudCompute
- Service Purpose: Firewalled / No Services
- Connection Type: Cloud-hosted
- Is CDN: No
- Is Proxy/VPN/Tor: No
- Is Mobile/Residential: No
- DNS Classification: Forward-confirmed reverse DNS
DNS & Hostname Resolution:
- PTR Record: ec2-35-77-156-228.ap-northeast-1.compute.amazonaws.com
- Forward Resolution: Confirmed (amazonaws.com)
- Forward Hostnames: 1 (EC2 compute endpoint)
- Email Auth: SPF present, DMARC present
## Threat Intelligence Assessment
Threat Indicators:
- Threat Indicators: None detected
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
- Known Campaigns: None
- Is Tor Exit Node: No
- Is Known Attacker: No
- Is Spam Source: No
Control Plane Data:
- BGP Prefix: 35.72.0.0/13
- Route Stability: Unstable
- RPKI State: Not available
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 lists (likely administrative)
- Operator Score: 0.2609 (Basic)
- Threat Observation Count: 1
Network Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Server Banner: None
## Neighborhood Analysis
Subnet Overview (35.77.156.228/24):
- Abuse Density: 0 (Low)
- Classification: Mostly Clean
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 1
The /24 subnet shows minimal abuse activity with no active sibling IPs under investigation.
## Observation History
Total Observations: 23 signals
Recent Activity (2026-06-18):
- 07:40:58 JST: Port scanning detected (multiple ports probed)
- 07:06:55 JST: Subnet classification updated (abuse density: 1)
- 07:06:13 JST: Ownership stability confirmed (0 changes)
- 07:01:35 JST: Threat list status checked (no matches)
- 06:53:44 JST: Operator score calculated (0.2609)
Temporal Indicators:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: No
## Relationship Graph
Total Relationships: 41
- Same Network: AMAZON-NRT (2 entries)
- DNS Association: ec2-35-77-156-228.ap-northeast-1.compute.amazonaws.com (3+ entries)
All relationships map to legitimate AWS infrastructure, with no external threat correlations.
## Recommended Actions
Security Recommendations: None
- Risk score (25) indicates low threat level
- No firewall rules required
- No blocking action recommended
SOC Analyst Guidance:
- Monitor as standard cloud infrastructure
- No immediate threat response required
- Include in baseline cloud traffic monitoring
- No evidence of compromise or malicious use
---
*Intelligence generated from IPDebrief threat intelligence platform. Data current as of 2026-06-18.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Data Services Japan |
| ASN | AS16509 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-35-77-156-228.ap-northeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-35-77-156-228.ap-northeast-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:17 UTC |
| Last Seen | 2026-06-27 05:04:17 UTC |
| Profile Built | 2026-06-27 23:11:06 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.