IP address 52.42.176.72 was identified as a Low Risk host with a risk score of 25. Ownership records attributed the address to Amazon Technologies Inc. (AS16509), geolocated to Portland, OR, United States. Network scans revealed open port 443 (HTTPS) with an HTTP/2.0 stack, while the TLS certificate subject indicated affiliation with Samsung Electronics Co., Ltd. in South Korea. This discrepancy resulted in conflicting geolocation signals. The asset appeared on one of eight DNS blacklists and was classified as a Suspicious Host with moderate attribution confidence. Behavioral analysis detected zero active incidents or known attacker activity. DNS hygiene scoring was rated Good with valid SPF and DMARC records present. Analysts recommended monitoring the asset due to signal contradictions between US-based geolocation and Korean certificate metadata, despite the overall low severity rating.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 52.0.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-52-42-176-72.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-52-42-176-72.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungcloud.comsamsungcloud.com |
| Valid From | 2026-09-07T00:00:00+00:00 |
| Valid Until | 2027-03-24T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 7AFA9F14AE3DDA1FB02ADB5E78837276 |
| Thumbprint | AF00399B14B8835A96E0387655E1630BD2668B21 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 50% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 28% | 8 | 9 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-09-26 20:14:45 UTC |
| Last Seen | 2026-09-26 20:14:45 UTC |
| Profile Built | 2026-09-26 20:35:04 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 25 |
Full dossier details are available via our API.