Intelligence Briefing: 54.216.167.104/32
Threat Status
The address was classified as Low Risk with a risk score of 25. Threat intelligence feeds returned no known indicators, blacklist listings, or active campaign matches. The system was not identified as a known attacker, spam source, or Tor exit node.
Infrastructure and Location
Ownership records linked the IP to Amazon.com, Inc. (ASN 16509) within the 54.216.0.0/15 CIDR block. Geolocation data placed the host in Dublin, Ireland (IE), though the TLS certificate indicated a connection to Samsung Electronics Co., Ltd. in Gyeonggi-do, KR.
Technical Profile
Network scans revealed open ports 80 (HTTP) and 443 (HTTPS) with an Apache server banner. DNS resolution confirmed the hostname ec2-54-216-167-104.eu-west-1.compute.amazonaws.com. Behavioral analysis recorded zero honeypot hits, enumeration strikes, or WAF violations.
Assessment and Recommendation
Operational assessment noted mixed signals due to geographic discrepancies and a lack of historical threat persistence. The network role was categorized as a web server with an abuse density of 0 in the local subnet. Analysts were advised to Monitor the address at low severity pending resolution of signal contradictions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZO-ZDUB3 |
| CIDR Block | 54.216.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-54-216-167-104.eu-west-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-54-216-167-104.eu-west-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/4 domains |
| DMARC | 2/4 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 4 domains |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | *.samsungapps.comsamsungapps.com |
| Valid From | 2026-01-27T00:00:00+00:00 |
| Valid Until | 2027-02-27T23:59:59+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 396 days |
| Serial Number | 064772DF706B47674722C1834FCBB1A6 |
| Thumbprint | EAD7059B63800BE769A6AE97EBE740532E38D9C9 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 33% | 2 | 4 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims KR but primary geo says IE
๐ Observation Timeline ๐ Live
| First Seen | 2026-09-01 09:00:19 UTC |
| Last Seen | 2026-09-16 05:36:14 UTC |
| Profile Built | 2026-09-16 05:40:34 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 39 |
Full dossier details are available via our API.