Intelligence analysis identified IP 54.220.181.213 as infrastructure owned by Amazon.com, Inc. (ASN 16509) within the 54.220.0.0/16 CIDR block. Reverse DNS resolution confirmed the host as ec2-54-220-181-213.eu-west-1.compute.amazonaws.com. Network scanning revealed standard web services on TCP ports 80 and 443, with TLS certificates issued by Sectigo for the *.push.samsungosp.com domain.
Threat assessment indicated a low-risk reputation score of 25 with no known campaign associations or active attacker flags. However, data analysis flagged signal contradictions regarding geolocation (sources disagreed between Ireland and South Korea) and certificate country attribution. The assessment concluded no immediate threat action was required, but monitoring is recommended due to signal inconsistencies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amazon.com, Inc. |
| ASN | AS16509 |
| Network Name | AMAZO-ZDUB4 |
| CIDR Block | 54.220.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ec2-54-220-181-213.eu-west-1.compute.amazonaws.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ec2-54-220-181-213.eu-west-1.compute.amazonaws.com |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 4/4 domains |
| DMARC | 2/4 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 4 domains |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | *.push.samsungosp.compush.samsungosp.com |
| Valid From | 2025-11-17T00:00:00+00:00 |
| Valid Until | 2026-12-18T23:59:59+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 396 days |
| Serial Number | 163F914E35AFA5204EAE5DC0D06733D3 |
| Thumbprint | 1565E26D89D47C1A2980DCF56D0FCD39AC1E4E91 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 5 |
| routing | 30% | 3 | 4 |
| services | 38% | 2 | 5 |
| ownership | 30% | 3 | 4 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 4 |
| Overall | 31% | 13 | 25 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims KR but primary geo says IE
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-29 12:40:36 UTC |
| Last Seen | 2026-09-15 05:14:22 UTC |
| Profile Built | 2026-09-15 05:23:25 UTC |
| Data Freshness | Live |
| Signal Types | 31 |
| Total Observations | 49 |
Full dossier details are available via our API.