The IP address 44.254.239.72/32 was identified as infrastructure belonging to Amazon.com, Inc. (ASN 16509) within the 44.224.0.0/11 CIDR block. Geolocation data located the host in Portland, Oregon, United States, and DNS resolution confirmed the address as an EC2 compute instance. The IP received a Low Risk reputation score of 25 with zero open ports detected and no active services observed.
Threat actor classification labeled the host as "Suspicious Host" despite the absence of specific campaign correlations or known attacker flags. Control plane data indicated one DNSBL listing among eight total lists, and the neighborhood analysis showed zero threat siblings. The recommendation indicated monitoring the traffic with a severity rating of low due to low-grade risk indicators present. The data freshness indicated live signals as of the latest observation window.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZO-ZPDX |
| CIDR Block | 44.224.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-44-254-239-72.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-44-254-239-72.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | awselb/2.0 |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungcloud.comsamsungcloud.com |
| Valid From | 2026-03-13T00:00:00+00:00 |
| Valid Until | 2026-09-27T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 00F405307E43CED6E95FD2C2DC61241722 |
| Thumbprint | 553F19DE95AB398DA86102FC2A332712DBC20858 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 33% | 2 | 4 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 33% | 2 | 4 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-09-09 20:00:30 UTC |
| Last Seen | 2026-09-18 07:23:14 UTC |
| Profile Built | 2026-09-18 07:44:26 UTC |
| Data Freshness | Live |
| Signal Types | 29 |
| Total Observations | 36 |
Full dossier details are available via our API.