IP INTELLIGENCE BRIEFING: 52.35.118.240/32
Classification: LOW RISK
1. IP Identity & Ownership
The IP address 52.35.118.240 resolves to Amazon Technologies Inc. (ASN 16509). The address belongs to AWS Cloud Compute infrastructure deployed in the US region, specifically Portland, OR. The IP operates as an AWS EC2 instance with hostname ec2-52-35-118-240.us-west-2.compute.amazonaws.com.
2. Risk Assessment
Current risk score: 25 (Low Risk). The IP exhibits no active threat indicators. Abuse confidence scoring was not triggered. The IP is not listed on major threat feeds, is not a known attacker, does not originate spam traffic, and is not a Tor exit node.
3. Network Classification
The address classifies as cloud infrastructure with the following flags:
- Provider: Amazon Web Services
- Infrastructure Type: CloudCompute
- Hosting: Enabled
- Services: None detected (Firewalled / No Services)
- Anycast: No
- Mobile/Residential: No
- Bogon: No
4. Control Plane & Routing
Origin ASN: 16509 (Amazon.com, Inc.)
BGP Prefix: 52.32.0.0/11
The IP has been observed with 1 DNSBL listing out of 8 total lists checked. Route stability has not been maintained. RPKI validation state was not determined.
5. DNS & Email Reputation
Reverse DNS resolves to: ec2-52-35-118-240.us-west-2.compute.amazonaws.com
Forward DNS resolution: Confirmed
Email authentication (SPF/DMARC): Not evaluated
Total hosted domains: 0
6. Neighborhood Analysis
The /24 subnet (52.35.118.0.0/24) shows 0 abuse density. No neighboring IPs were flagged as high or medium risk. The classification indicates the subnet is mostly clean.
7. Historical Behavior
Signal observation history contains 23 observations across multiple timestamps. The IP consistently resolves to ASN 16509 (Amazon). Operator score remained at 0.2609 (Basic) in historical signals. No persistent malicious activity or threat campaigns were observed.
8. Related Entities
The IP maintains 78 relationships in the relationship graph, including DNS associations and multiple same-network links. No certificate relationships or organization-specific links were identified beyond the AWS network.
9. Recommended Actions
No specific firewall rules or blocking actions recommended. The IP presents no active threat indicators and operates within expected AWS infrastructure parameters. Standard egress/ingress rules for cloud compute traffic apply.
10. Intelligence Summary
52.35.118.240 is a legitimate AWS EC2 instance with no evidence of malicious activity. The IP shows stable ownership, clean neighborhood metrics, and no historical threat indicators. No SOC alert or blocking action required.
Analyst Notes: Monitor for changes in risk score or emergence of threat indicators. The IP should be treated as standard cloud infrastructure traffic.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-52-35-118-240.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-52-35-118-240.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 20% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-13 12:13:36 UTC |
| Last Seen | 2026-06-27 23:28:45 UTC |
| Profile Built | 2026-06-28 23:33:43 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.