# IP Intelligence Briefing: 52.78.63.73/32
Classification: LOW RISK
Date: 2026-06-15
Prepared For: SOC Operations Team
---
## Executive Summary
IP 52.78.63.73 is identified as an Amazon Web Services EC2 instance deployed in the Asia Pacific (Seoul) Region (ap-northeast-2). The IP presents a low-risk profile with no active threat indicators, no open ports, and no blacklist associations. No blocking action is currently recommended.
---
## Infrastructure Profile
- IP Address: 52.78.63.73/32
- Risk Score: 25/100 (Low Risk)
- Provider: Amazon Web Services (ASN 16509)
- Organization: AWS Asia Pacific (Seoul) Region
- BGP Prefix: 52.78.0.0/16
- Geolocation: Seoul, South Korea (KR)
- Hostname: ec2-52-78-63-73.ap-northeast-2.compute.amazonaws.com
- Infrastructure Type: Cloud Hosting (EC2 Instance)
---
## Threat Assessment
- Abuse Confidence: Not applicable (low-risk infrastructure)
- Blacklist Status: Clean (0 blacklist entries)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: None detected
- Threat Persistence: 0 days (no persistent malicious activity observed)
---
## Network Services & Exposure
- Open Ports: None detected
- Service Banner: None (firewalled/no services exposed)
- TLS Certificate: Not detected
- HTTP Title: Not detected
- DNS Configuration: Properly configured with SPF and DMARC records
- DNS Resolution: Forward confirmed to expected hostname
---
## Control Plane Analysis
- DNSSEC Valid: Yes
- Operator Score: 0.2609 (Basic classification)
- Route Stability: Not stable (0 route changes in 30 days)
- DNSBL Listed: 1 of 8 total lists (low-impact listing)
- RPKI/Irr: State not determinable
---
## Neighborhood Assessment
- Subnet: 52.78.63.73/24
- Abuse Density: 1 (low)
- Classification: mostly_clean
- Threat Siblings: 1 detected in subnet
- Inherited Risk: 2 (minimal)
---
## Historical Observations
- Observation Count: 20 signals
- Recent Activity: Signals observed as of 2026-06-15
- Threat Trend: Stable (no escalation detected)
- Ownership Changes: 0
- Persistently Malicious: No
---
## Related Entities
- DNS Associations: ec2-52-78-63-73.ap-northeast-2.compute.amazonaws.com
- Network Associations: AMAZON-ICN (Amazon Internet Cloud Network)
- Total Relationships: 29 (primarily DNS and network associations)
---
## Recommended Actions
- Immediate Blocking: Not recommended
- Monitoring Level: Standard traffic monitoring
- Firewall Rules: No specific rules required
- WAF Configuration: No special configuration needed
---
## Intelligence Notes
This IP represents standard AWS cloud infrastructure with appropriate security controls (SPF/DMARC). The absence of open ports indicates the instance is either non-public-facing or properly secured. The subnet shows minimal abuse density. No intelligence warrants additional scrutiny at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | AWS Asia Pacific (Seoul) Region |
| ASN | AS16509 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-52-78-63-73.ap-northeast-2.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-52-78-63-73.ap-northeast-2.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 47% | 1 | 5 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 27% | 10 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 18:41:32 UTC |
| Last Seen | 2026-06-29 00:40:39 UTC |
| Profile Built | 2026-06-29 06:43:50 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.