IP INTELLIGENCE BRIEFING: 44.220.185.12
---
EXECUTIVE SUMMARY
IP 44.220.185.12 is classified as MODERATE RISK (score: 40/100). The IP is hosted on Amazon Web Services infrastructure in Ashburn, VA and is associated with a high-abuse-density subnet (44.220.185.0/24). While the IP itself shows no known malicious indicators, the network neighborhood exhibits elevated abuse activity warranting defensive monitoring.
OWNERSHIP & INFRASTRUCTURE
- ASN: 14618 (Amazon Data Services Northern Virginia)
- Organization: AMAZON-IAD
- CIDR Block: 44.192.0.0/11
- Infrastructure Type: Cloud Compute / Single-Service Host
- Location: Ashburn, VA, US (N. America)
- Geolocation Confidence: High (consensus validated)
NETWORK SIGNATURES
- PTR Hostname: scanner-44-220-185-12.reposify.net
- Service: HTTP/1.0 (Port 80/tcp)
- Server Banner: Reposity
- HTTP Status: 200 OK
- DNSSEC: Valid
THREAT ASSESSMENT
- Risk Score: 40/100 (Moderate)
- Abuse Confidence: Not applicable
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Status: 0 lists
- DNSBL Listed: 1 of 8 lists
- Campaign Association: None detected
- Persistent Malicious Behavior: No
NEIGHBORHOOD ANALYSIS
Subnet 44.220.185.0/24 shows elevated abuse activity:
- Abuse Density: 0.5556 (high_abuse classification)
- Total Siblings: 27
- Active Siblings: 16
- Threat Siblings: 15
- Risk Distribution: 0 High | 10 Medium | 19 Low
OBSERVATION HISTORY
- Total Observations: 24
- Recent Signals: Network-level routing and subnet abuse density signals detected between 2026-06-16 and 2026-06-21
- Ownership Changes: None (stable)
- Threat Persistence: 0 days
- Observation Count: 1
RELATIONSHIP MAPPING
- Primary Associations: Same network (AMAZON-IAD)
- DNS Associations: scanner-44-220-185-12.reposify.net
- Correlated Entities: Multiple hostname and network associations within same infrastructure
RECOMMENDED ACTIONS
Based on the moderate risk profile and neighborhood context, the following firewall rules are recommended:
Recommended Block Rule:
```bash
# iptables
iptables -A INPUT -s 44.220.185.12 -j DROP
# nftables
nft add rule inet filter input ip saddr 44.220.185.12 drop
# nginx
deny 44.220.185.12;
# pfSense
44.220.185.12/32
# Cloudflare WAF
Block 44.220.185.12 β IPDebrief risk score 40
# AWS WAF
Addresses: ["44.220.185.12/32"]
```
INTEL CONCLUSION
This IP represents a moderate-risk infrastructure host within an abuse-prone subnet. While the IP shows no direct malicious indicators, the neighborhood context suggests potential for abuse. Implementing the recommended block rule is advised, particularly for high-traffic or security-sensitive endpoints. Monitor for any behavioral changes or correlation with known threat actor infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Northern Virginia |
| ASN | AS14618 |
| Network Name | AMAZON-IAD |
| CIDR Block | 44.192.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | scanner-44-220-185-12.reposify.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | scanner-44-220-185-12.reposify.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Reposify |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-04 00:32:33 UTC |
| Last Seen | 2026-06-21 11:05:25 UTC |
| Profile Built | 2026-06-21 11:21:21 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 31 |
Full dossier details are available via our API.