# IP Intelligence Briefing: 52.64.138.220/32
Classification: LOW RISK โ Legitimate AWS Cloud Infrastructure
Analysis Date: Current
---
## Executive Summary
IP 52.64.138.220 is a low-risk address assigned to Amazon Web Services (AWS) EC2 infrastructure. The IP shows no malicious indicators, is not associated with known threat campaigns, and operates within clean cloud infrastructure. No immediate defensive action required.
---
## Ownership & Network Context
- Owner: Amazon Technologies Inc. (ASN 16509)
- Network Block: 52.0.0.0/10 (AT-88-Z)
- Geolocation: Sydney, New South Wales, Australia (ap-southeast-2 region)
- Infrastructure Type: CloudCompute (AWS EC2 instance)
- Classification: Cloud-hosted, not residential, proxy, VPN, or Tor exit
---
## Threat Assessment
| Indicator | Status |
|---|---|
| Risk Score | 25/100 (Low Risk) |
| Abuse Confidence | Not flagged |
| Blacklist Count | 0 |
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
Threat Feeds: No indicators from Pulsedive or other threat intelligence sources. No known campaign associations.
---
## Technical Profile
- DNS Resolution: ec2-52-64-138-220.ap-southeast-2.compute.amazonaws.com
- PTR Hostnames: ec2-52-64-138-220.ap-southeast-2.compute.amazonaws.com
- Open Ports: None detected (firewalled/no services exposed)
- TLS/Certificates: Not detected
- Reverse DNS: Forward-confirmed
- Email Auth: SPF and DMARC records present for associated domain
---
## Neighborhood Analysis
- Subnet: 52.64.138.220/24
- Abuse Density: 0 (clean subnet)
- Threat Siblings: 0
- Neighbor Risk Distribution: None detected
---
## Historical Observations
22 historical signals observed. Recent activity shows consistent cloud infrastructure classification. Earlier observations included geolocation signals from multiple regions (including New York, US) and traceroute attempts, which are typical for cloud environments. No escalation in threat indicators over time.
---
## Relationships
- 14 recorded relationships
- Primary associations: Same network (AT-88-Z) and DNS hostname mappings
- No anomalous external entity associations detected
---
## SOC Recommendations
No blocking or filtering recommended. This IP represents legitimate AWS infrastructure with no threat indicators. If traffic is observed from this address:
1. Allow inbound/outbound traffic (unless organizational policy restricts cloud provider access)
2. Monitor for unusual connection patterns if this IP is not an expected partner/service
3. No firewall rules required unless specific business logic dictates cloud traffic restrictions
---
Conclusion: This IP address is a standard AWS EC2 instance in the Sydney region. The profile indicates normal cloud infrastructure operation with no malicious activity observed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AT-88-Z |
| CIDR Block | 52.0.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-52-64-138-220.ap-southeast-2.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-52-64-138-220.ap-southeast-2.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:34:31 UTC |
| Last Seen | 2026-08-12 23:35:29 UTC |
| Profile Built | 2026-08-12 23:44:09 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.