Intelligence assessment for IP 44.227.6.101/32 classified the address as Low Risk with a risk score of 25. Geolocation data placed the infrastructure in Portland, Oregon, United States. DNS resolution confirmed the address belonged to Amazon Web Services, specifically an EC2 instance in the us-west-2 region. Network scanning detected no open ports or active services. The IP was not listed as a known attacker or spam source, though it appeared on one of eight DNS blocklists. The surrounding subnet (44.227.6.0/24) remained clean with zero abuse density. Behavioral analysis recorded zero honeypot hits, enumeration strikes, or WAF violations. Analysts recommended monitoring the address due to the single DNSBL listing, maintaining a low severity rating given the clean neighborhood context and lack of specific threat actor attribution.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZO-ZPDX |
| CIDR Block | 44.224.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-44-227-6-101.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Hosted Domain | ec2-44-227-6-101.us-west-2.compute.amazonaws.com |
| Hosted Domain | gobiomdb-573045446.us-west-2.elb.amazonaws.com |
| Forward Hostnames | ec2-44-227-6-101.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungcloud.comsamsungcloud.com |
| Valid From | 2026-09-07T00:00:00+00:00 |
| Valid Until | 2027-03-24T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 7AFA9F14AE3DDA1FB02ADB5E78837276 |
| Thumbprint | AF00399B14B8835A96E0387655E1630BD2668B21 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-09-25 10:47:53 UTC |
| Last Seen | 2026-09-25 10:47:53 UTC |
| Profile Built | 2026-09-25 10:57:44 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.