# IP INTELLIGENCE BRIEFING: 54.171.115.210/32
Classification: Moderate Risk | Date: Current Analysis
## EXECUTIVE SUMMARY
IP address 54.171.115.210 is identified as an Amazon Web Services EC2 instance hosted in the Dublin region (eu-west-1). The asset carries a moderate risk score (50/100) primarily attributable to DNSBL listings (2 out of 8 lists). No active threat indicators, campaigns, or malicious behavior detected. No open ports or services observed.
## OWNERSHIP & INFRASTRUCTURE
- ASN: 16509 (Amazon Technologies Inc.)
- Organization: AMAZON
- CIDR Block: 54.144.0.0/12
- Network Role: Amazon Web Services
- BGP Prefix: 54.171.0.0/16
- RIR: ARIN
- DNS Hostname: ec2-54-171-115-210.eu-west-1.compute.amazonaws.com
- Geolocation: Dublin, Leinster, Ireland (IE)
## NETWORK CLASSIFICATION
| Attribute | Status |
|---|---|
| Cloud Infrastructure | Yes (AWS EC2) |
| CDN | No |
| Proxy/Tor | No |
| Open Ports | None Detected |
| Active Services | None Detected |
| TLS Certificate | None |
| Anycast | No |
## THREAT POSTURE
- Risk Score: 50 (Moderate)
- Abuse Confidence Score: Not applicable
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 active blacklists
- DNSBL Listed: 2 of 8 lists
- Known Campaigns: None
- Threat Feeds: None
## OBSERVATION HISTORY (17 Total Observations)
Recent signal observations recorded on 2026-07-31:
1. Geolocation Conflicts: Multiple geolocation sources report conflicting data:
- MaxMind GeoLite2: Dublin, Ireland (EU)
- Cymru Country: United States (US)
- Multiple ARIN/AS lookup sources confirm Amazon ownership
2. Ownership Stability: Zero ownership changes detected. Persistent ownership by Amazon Technologies Inc. confirmed.
3. Threat Persistence: Zero threat observation count; not persistently malicious.
## RELATIONSHIP ANALYSIS
Connected Entities (6 relationships):
- DNS Association: ec2-54-171-115-210.eu-west-1.compute.amazonaws.com
- Network Association: AMAZON (multiple entries)
Key Findings:
- Single hostname resolution
- No certificate associations
- No correlated malicious IPs
## NEIGHBORHOOD ANALYSIS
Subnet: 54.171.115.210/24
- Neighbor Count: 0
- Abuse Density: 0%
- Risk Distribution: No classified neighbors
- Active Siblings: None detected
## CONTROL PLANE DATA
- Origin ASN: 16509
- Route Stability: Unstable
- RPKI State: Not assessed
- DNSSEC: Valid
- HTTP/2: No
- HSTS: No
## RECOMMENDATIONS
Immediate Actions:
1. Monitor DNSBL Listings: Investigate the 2 DNSBL listings to determine source and remediation requirements.
2. Verify Service Status: No services detected; confirm if this is intended behavior for the workload.
3. Geolocation Validation: Geographic inconsistency between sources warrants periodic re-verification.
Long-Term Monitoring:
1. Track DNSBL status changes over 30-day period
2. Monitor for service activation (open ports, TLS certificates)
3. Continue observation of geolocation signals for consistency
## INTELLIGENCE NOTES
This IP represents legitimate AWS infrastructure with a moderate risk rating driven by DNSBL listings rather than active malicious behavior. The absence of open ports and services suggests this may be a dormant, reserved, or heavily restricted EC2 instance. The DNSBL listings warrant investigation but do not indicate active threat activity. Geographic signal conflicts are common in cloud environments and should be validated through additional sources if critical for attribution.
Status: Monitor | Confidence: High | Threat Level: Low
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon Technologies Inc. |
| ASN | AS16509 |
| Network Name | AMAZON |
| CIDR Block | 54.144.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-54-171-115-210.eu-west-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-54-171-115-210.eu-west-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 11:04:15 UTC |
| Last Seen | 2026-08-13 00:43:09 UTC |
| Profile Built | 2026-08-13 01:13:33 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 35 |
Full dossier details are available via our API.