# IP Intelligence Briefing: 52.79.233.127/32
## Executive Summary
The IP address 52.79.233.127 is a low-risk infrastructure endpoint hosted in AWS Asia Pacific (Seoul) Region. The address resolves to an EC2 compute instance with no detected open ports or active services. Current risk assessment indicates minimal threat activity.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 52.79.233.127/32 |
| **Risk Score** | 25 (Low Risk) |
| **Provider** | Amazon Web Services (AWS) |
| **Organization** | AWS Asia Pacific (Seoul) Region |
| **ASN** | 16509 |
| **CIDR Block** | 52.79.0.0/16 |
| **Country** | KR (Korea) |
| **City** | Seoul |
| **Registration** | RIR: ARIN |
---
## Network Classification
- Infrastructure Type: Cloud Infrastructure (AWS EC2)
- DNS Record: ec2-52-79-233-127.ap-northeast-2.compute.amazonaws.com
- Open Ports: None detected
- Active Services: None detected (Firewalled)
- Known Threats: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## Threat Indicators
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
- Known Campaigns: None
- Threat Feeds: None
- DNSBL Listings: 1 of 8 total lists (historical observation 2026-06-12)
---
## Neighborhood Analysis (52.79.233.0/24)
- Abuse Density: 0%
- Classification: Clean
- Total Neighbors: 1
- Neighbor IP: 52.79.233.225 (Risk Score: 50)
- Threat Siblings: 0
---
## Observation History
Temporal Activity: 18 historical observations recorded
- 2026-06-21 (Most Recent):
- Geolocation: Seoul, KR (56% confidence, 150km accuracy)
- Operator Score: Basic (0.2609)
- Network Classification: AWS infrastructure confirmed
- No malicious activity detected
- 2026-06-12:
- Blacklist listing observed (1 of 8 lists, high severity classification)
- Historical artifact; no current correlation
---
## Relationships Graph
- Total Relationships: 16
- Network Associations: Multiple "Same Network" links to AMAZON-ICN
- DNS Associations: Consistent resolution to ec2-52-79-233-127.ap-northeast-2.compute.amazonaws.com
- No Cross-Organization Links: All relationships contained within AWS infrastructure
---
## Recommended Actions
Risk Level: LOW (Score: 25)
- Firewall Rules: None required
- Monitoring: Standard logging recommended for baseline
- Blocking: Not recommended; IP represents legitimate cloud infrastructure
Note: No specific actionable recommendations generated. IP demonstrates normal AWS EC2 behavior with no current threat indicators.
---
## SOC Analyst Notes
This IP address represents a standard AWS cloud compute instance in the Seoul region. The low risk score (25) and absence of open ports indicate proper security posture. The single neighbor IP (52.79.233.225) shows elevated risk (50) and may warrant separate investigation if traffic patterns suggest correlation. No immediate threat mitigation required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | AWS Asia Pacific (Seoul) Region |
| ASN | AS16509 |
| Network Name | AMAZON-ICN |
| CIDR Block | 52.79.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-52-79-233-127.ap-northeast-2.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-52-79-233-127.ap-northeast-2.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 17% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-03 12:22:15 UTC |
| Last Seen | 2026-06-29 12:42:39 UTC |
| Profile Built | 2026-06-29 12:46:43 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.