Intelligence analysis identified IP 54.213.152.221 as a web server hosted on Amazon Web Services infrastructure within the Amazon.com, Inc. network. The host resolved to ec2-54-213-152-221.us-west-2.compute.amazonaws.com and presented an HTTP 404 response on TCP port 443. A TLS certificate issued by Sectigo Limited was observed, claiming affiliation with Samsung Electronics Co. Ltd. in Gyeonggi-do, South Korea, while geolocation data placed the infrastructure in Portland, Oregon, United States.
Risk assessment assigned a low-risk reputation score of 25. The IP was listed on one DNS blacklist out of eight checked and was categorized as a Suspicious Host. Behavioral analysis recorded no honeypot hits, enumeration strikes, or known campaign correlations. The profile exhibited mixed signals with a coherence score of 68 due to geographic contradictions.
Due to conflicting data and signal contradictions, the recommended action was to monitor the asset. Overall data confidence was rated as very low.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZO-ZPDX5 |
| CIDR Block | 54.212.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-54-213-152-221.us-west-2.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-54-213-152-221.us-west-2.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.samsungcloud.comsamsungcloud.com |
| Valid From | 2026-03-13T00:00:00+00:00 |
| Valid Until | 2026-09-27T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 00F405307E43CED6E95FD2C2DC61241722 |
| Thumbprint | 553F19DE95AB398DA86102FC2A332712DBC20858 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims KR but primary geo says US
π Observation Timeline π Live
| First Seen | 2026-09-05 13:52:05 UTC |
| Last Seen | 2026-09-13 02:44:17 UTC |
| Profile Built | 2026-09-13 02:50:08 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 30 |
Full dossier details are available via our API.