Intelligence analysts profiled IP 54.220.170.166/32 as Low Risk with a risk score of 0. The address is owned by Amazon.com, Inc. (ASN 16509) within the 54.220.0.0/16 CIDR block. Geolocation data placed the host in Dublin, Ireland, with a forward-confirmed reverse DNS entry resolving to ec2-54-220-170-166.eu-west-1.compute.amazonaws.com.
Threat analysis revealed no indicators of compromise, blacklist listings, or abuse confidence scores. The network role is classified as CloudCompute infrastructure with a service purpose of "Firewalled / No Services." Behavioral data showed zero honeypot hits, enumeration strikes, or total incidents. The system recorded zero threat persistence days and zero threat observation count.
The intent classification is Legitimate Infrastructure. Operational confidence labels the data as Live. Analysts recommend allowing traffic with an info-level severity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZO-ZDUB4 |
| CIDR Block | 54.220.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-54-220-170-166.eu-west-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-54-220-170-166.eu-west-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | apiproxy-nrdp-s2.eu-west-1.dynprod.netflix.netapiproxy-nrdp-s2.dynprod.netflix.netapiproxy-nrdp-s2.netflix.netnrdp.apiproxy.eu-west-1.dynprod.netflix.netapiproxy.app.eu-west-1.prod.cloud.netflix.netapiproxy.netflix.netnrdp-s2.apiproxy.netflix.netnrdp-s2.apiproxy.eu-west-1.prod.netflix.netnrdp-s2.apiproxy.prod.netflix.netnrdp.apiproxy.eu-west-1.prod.netflix.net |
| Valid From | 2026-09-24T23:20:10+00:00 |
| Valid Until | 2026-10-02T00:20:10+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256ECDSA |
| Validity Period | 7 days |
| Serial Number | 01B8E01071709CA3611302726D49BD1FDEB1 |
| Thumbprint | 47136ACF00C1CB1C87100AE3A7854F3CA7E1D623 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 20% | 1 | 1 |
| services | 40% | 2 | 3 |
| ownership | 40% | 2 | 3 |
| reputation | 20% | 1 | 2 |
| geolocation | 43% | 2 | 3 |
| Overall | 33% | 10 | 15 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims US but primary geo says IE
๐ Observation Timeline ๐ Live
| First Seen | 2026-09-25 01:47:30 UTC |
| Last Seen | 2026-09-27 03:32:41 UTC |
| Profile Built | 2026-09-27 03:37:32 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 30 |
Full dossier details are available via our API.