IPDebrief

35.90.87.249

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP Intelligence Briefing: 35.90.87.249

Classification: LOW RISK β€” AWS Cloud Infrastructure

Report Date: Current

Risk Score: 25/100

---

Executive Summary

IP address 35.90.87.249 belongs to Amazon Web Services (AWS) cloud infrastructure and presents a low-risk threat profile. The address resolves to an Amazon EC2 instance in the US West (Oregon) region with no active threat indicators or malicious behavior observed.

---

Infrastructure Profile

The IP address is classified as cloud infrastructure operating within the Amazon Web Services network (ASN 16509, Organization: Amazon.com, Inc.). The CIDR block 35.80.0.0/12 indicates this is part of a larger AWS infrastructure deployment. Geolocation data consistently places the address in Portland, Oregon, with coordinates 45.59, -122.6.

Key Attributes:

---

Threat Analysis

Threat indicators returned empty with zero blacklist entries. The IP is not flagged as a Tor exit node, known attacker, or spam source. Abuse confidence score is unavailable, and no known campaigns correlate with this address.

Control Plane Data:

---

Historical Observation

Analysis of 21 historical observations reveals consistent infrastructure classification. Recent signals (June 2026) confirm AWS cloud infrastructure status with 85-90% confidence. Historical pulses detected on June 20, 2026, included three threat-related pulse names, though no specific campaigns were identified.

Geographic consistency maintained throughout the observation period, with multi-signal inference consistently placing the IP in the Portland, OR region. Operator scoring remained stable at 0.2609.

---

Network Relationships

The IP maintains 32 documented relationships, predominantly DNS associations to the same EC2 hostname. Network-level associations link to the AMAZON-ZPDX subnet. No external organization or certificate relationships detected beyond AWS infrastructure.

---

Neighborhood Assessment

The /24 subnet (35.90.87.0/24) shows abuse density of 0 with classification "mostly_clean." No active sibling neighbors detected. Historically, 1 threat sibling has been observed in the neighborhood.

---

Recommended Security Actions

Risk assessment of 25/100 indicates minimal threat. No specific firewall rules or blocking actions recommended. Standard monitoring of AWS cloud infrastructure traffic is appropriate.

Recommended Actions:

---

Conclusion

IP 35.90.87.249 represents legitimate AWS cloud infrastructure with no current threat indicators. The low-risk classification and consistent infrastructure classification support continued monitoring without restrictive measures. SOC teams should treat traffic from this address as benign unless additional signals indicate otherwise.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionOR
CityPortland
TimezoneAmerica/Los_Angeles
Latitude45.59
Longitude-122.60

🏒 Ownership & Registration

OrganizationAmazon.com, Inc.
ASNAS16509
Network NameAMAZON-ZPDX
CIDR Block35.80.0.0/12
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-35-90-87-249.us-west-2.compute.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesec2-35-90-87-249.us-west-2.compute.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPF2/2 domains
DMARC1/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.0

πŸ” TLS Certificate

An expired certificate for CN=campaign.network was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
πŸ”’
CN=campaign.network
Issued by CN=R13, O=Let's Encrypt, C=US
Self-signed: No
SANscampaign.networkwww.campaign.network
Valid From2026-03-14T09:37:35+00:00
Valid Until2026-06-12T09:37:34+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number053A37B1CF9549824615ECCD4663CFF8A88E
ThumbprintE5095696993FD588191C70050AE7C4B0CE61B6CE

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
37%
24
routing
8%
11
services
37%
23
ownership
27%
23
reputation
32%
13
geolocation
34%
23
Overall29%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-25 12:42:33 UTC
Last Seen2026-06-29 01:42:39 UTC
Profile Built2026-06-29 07:45:06 UTC
Data FreshnessLive
Signal Types24
Total Observations27
πŸ” 24 signal types Β· 27 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.