## IP Intelligence Briefing: 35.86.166.206
Date: Analysis completed on 2026-08-13
Classification: Cloud Infrastructure (AWS EC2)
Risk Level: LOW (Score: 25/100)
Executive Summary
IP 35.86.166.206 is an Amazon Web Services cloud compute endpoint registered under ASN 16509 (Amazon.com, Inc.). The address resolves to hostname ec2-35-86-166-206.us-west-2.compute.amazonaws.com and is geolocated to the Portland, Oregon region (US-West-2). Current threat indicators show no active malicious behavior.
Ownership and Infrastructure
- Organization: Amazon.com, Inc.
- Network: AMAZON-ZPDX (35.80.0.0/12)
- Infrastructure Type: CloudCompute
- DNS Resolution: ec2-35-86-166-206.us-west-2.compute.amazonaws.com (forward confirmed)
- PTR Record: ec2-35-86-166-206.us-west-2.compute.amazonaws.com
Network Classification
| Attribute | Value |
|---|---|
| Is Cloud | Yes |
| Is Hosting | Yes |
| Is CDN | No |
| Is Proxy | No |
| Is Tor | No |
| Open Ports | None detected |
| DNSSEC | Valid |
| Route Stability | Unstable |
Threat Assessment
Current Risk Score: 25/100 (Low Risk)
- Blacklist Status: Not flagged on major threat feeds (blacklistCount: 0)
- Abuse Confidence Score: Not applicable
- Known Campaigns: None identified
- Tor/Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Indicators:
- Route changes (30-day window): 0
- Is MOAS: No
- DNSSEC Valid: Yes
- Operator Score: 0.2609 (Basic)
Observation History
25 historical observations recorded. Recent activity (2026-08-13) indicates:
- Abuse Density: 1
- Classification: Mostly clean
- Inherited Risk: 2
- Persistent Malicious Behavior: No
No sustained malicious activity detected. The IP shows typical cloud infrastructure behavior with no anomalous patterns.
Neighborhood Analysis
Subnet: 35.86.166.206/24
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Abuse Density: 0
- Risk Distribution: 0 high/medium, 0 low
The /24 subnet contains minimal threat activity, consistent with standard AWS infrastructure density.
Relationships
- Network Association: AMAZON-ZPDX (repeated)
- DNS Associations: ec2-35-86-166-206.us-west-2.compute.amazonaws.com (repeated)
- No external organizational or certificate relationships detected.
Recommended Actions
No immediate blocking or mitigation actions recommended. The IP exhibits standard cloud infrastructure characteristics without threat indicators.
Monitoring Suggestion: Continue passive monitoring. If the IP begins generating inbound connections or exhibiting scan activity, re-evaluate with increased frequency.
SOC Analyst Notes: This endpoint is a firewalled AWS EC2 instance with no active services exposed. The single DNSBL listing appears to be a false positive or historical artifact. No correlation to known threat campaigns or malicious infrastructure. Treat as benign cloud infrastructure unless behavioral changes are observed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZON-ZPDX |
| CIDR Block | 35.80.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-35-86-166-206.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-35-86-166-206.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 30% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-02 17:02:33 UTC |
| Last Seen | 2026-08-13 04:04:34 UTC |
| Profile Built | 2026-08-13 04:16:17 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.