Intelligence analysis identified IP 52.14.15.173/32 as part of Amazon Technologies Inc. infrastructure (AS16509). The asset located in Columbus, Ohio, within the 52.0.0.0/10 block operated as a Web Server. Operational data showed a single open port 443 (HTTPS) serving a TLS certificate issued by Samsung Electronics OCF Server SubCA for the domain *.samsungiotcloud.com. DNS records confirmed forward resolution via Amazon Web Services with SPF and DMARC authentication present.
The threat assessment classified the IP as Low Risk with a risk score of 0. No active threat indicators, blacklists, or campaign associations were detected. Behavioral analysis recorded zero honeypot hits, enumeration strikes, or incidents.
However, data coherence presented mixed signals. Geolocation sources conflicted regarding the country of origin, citing United States and South Korea. This contradiction appeared between the primary location data and the TLS certificate subject. The neighborhood analysis indicated a clean environment with zero threat siblings.
Recommendations indicated monitoring the asset due to signal contradictions, with a severity rating of low. The overall intent classification remained Legitimate Infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 52.0.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-52-14-15-173.us-east-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-52-14-15-173.us-east-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungiotcloud.com |
| Valid From | 2020-03-18T07:40:32+00:00 |
| Valid Until | 2035-04-09T07:40:32+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256ECDSA |
| Validity Period | 5500 days |
| Serial Number | 33DEF0C83047D74E |
| Thumbprint | 30AA82E4144123E889C449CD1F47CDC2F811A97D |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 33% | 2 | 4 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 1 |
| geolocation | 27% | 2 | 2 |
| Overall | 21% | 9 | 12 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-08-30 03:12:52 UTC |
| Last Seen | 2026-09-14 00:45:34 UTC |
| Profile Built | 2026-09-14 00:59:28 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.