Intelligence Briefing: 52.37.88.106/32
The IP address 52.37.88.106/32 was classified as Low Risk with a risk score of 25. Ownership records attributed the address to Amazon Technologies Inc. (ASN 16509) within the US-West-2 region in Portland, Oregon. Network scans revealed an active HTTPS service on port 443 presenting a TLS certificate for Samsung Cloud. Threat analysis indicated no known attacker associations or active campaigns, although one DNSBL listing was noted in control plane data. Geolocation validation failed, with sources disagreeing between the United States and South Korea, and the TLS certificate subject country contradicted the primary infrastructure location. Analysts recommended monitoring the asset due to mixed signals and data contradictions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 52.0.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-52-37-88-106.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-52-37-88-106.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungcloud.comsamsungcloud.com |
| Valid From | 2026-03-13T00:00:00+00:00 |
| Valid Until | 2026-09-27T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 00F405307E43CED6E95FD2C2DC61241722 |
| Thumbprint | 553F19DE95AB398DA86102FC2A332712DBC20858 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 29% | 2 | 4 |
| ownership | 30% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 29% | 12 | 21 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-09-06 15:41:26 UTC |
| Last Seen | 2026-09-15 11:00:42 UTC |
| Profile Built | 2026-09-15 11:18:04 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 37 |
Full dossier details are available via our API.