IPDebrief

54.246.58.140

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence assessment for 54.246.58.140 identified the system as a Web Server owned by Amazon Technologies Inc. (ASN 16509) within the 54.224.0.0/11 block. The infrastructure operated within the eu-west-1 region (Dublin, IE), resolving to an EC2 instance via standard AWS routing. Open port 443 served HTTPS traffic utilizing an Envoy server banner.

Analysis revealed a significant infrastructure contradiction. The TLS certificate subject identified Netflix Inc (OU=Platform Security), validating hostnames such as logging.apiproxy.eu-west-1.prod.netflix.net, while the IP ownership remained Amazon-hosted. Geolocation sources conflicted regarding the physical location, reporting inconsistencies between US, GB, and IE despite the certificate indicating a US origin.

Threat analysis indicated no active malicious activity. The IP held a Low Risk reputation score of 25 with zero blacklist hits and no association with known campaigns. Behavioral monitoring recorded no honeypot strikes or WAF violations. Given the infrastructure contradictions and the presence of Netflix-specific certificates on AWS hosting, the recommendation was to monitor traffic without immediate remediation.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡ช Ireland
RegionD
CityDublin
TimezoneEurope/Dublin
Latitude53.35
Longitude-6.26

๐Ÿข Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS16509
Network NameAMAZON-2011L
CIDR Block54.224.0.0/11
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRec2-54-246-58-140.eu-west-1.compute.amazonaws.com
Forward ConfirmedYes โ€” FCrDNS verified
Hosted Domainapiproxy-logging-s1-bc2f1b420f34a65d.elb.eu-west-1.amazonaws.com
Hosted Domainec2-54-246-58-140.eu-west-1.compute.amazonaws.com
Forward Hostnamesec2-54-246-58-140.eu-west-1.compute.amazonaws.com

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPF6/6 domains
DMARC6/6 domains
FCrDNSVerified
DNSSECNot signed
CAANot configured
Domains Checked6 domains

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpโ€”
Closed Ports22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned)
Serverenvoy
HTTP Titleโ€”

๐Ÿ” TLS Certificate

An expired certificate for SERIALNUMBER=i-0100cbb850fc858b7, OU=Platform Security, O=Netflix Inc, L=Los Gatos, S=California, C=US was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
๐Ÿ”’
SERIALNUMBER=i-0100cbb850fc858b7, OU=Platform Security, O=Netflix Inc, L=Los Gatos, S=California, C=US
Issued by E=platformsecurity@netflix.com, OU=Platform Security, O=Netflix Inc, CN=Netflix Internal Services Intermediate Prod CA V10, L=Los Gatos, S=California, C=US
Self-signed: No
SANslogging.apiproxy.eu-west-1.prod.netflix.netlogging.apiproxy.netflix.netapiproxy.app.eu-west-1.prod.cloud.netflix.netapiproxy.netflix.netapiproxy-logging.eu-west-1.prod.netflix.netapiproxy-logging.dynprod.netflix.netlogging.apiproxy.dynprod.netflix.netapiproxy-logging.prod.netflix.netapiproxy.eu-west-1.dynprod.netflix.netapiproxy.eu-west-1.prod.netflix.net
Valid From2026-09-07T03:28:26+00:00
Valid Until2026-09-14T04:28:26+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256ECDSA
Validity Period7 days
Serial Number0102FE57B8EC61B1598A5A33BFF97F0E4641
Thumbprint8087E5A3D2B4C428674521BA43ED451CF597E9BE

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
38%
25
routing
13%
11
services
33%
25
ownership
27%
24
reputation
22%
13
geolocation
27%
23
Overall27%1021
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) โ€” 2 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, IE
โš  TLS certificate claims US but primary geo says IE

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-08-30 02:58:00 UTC
Last Seen2026-09-23 01:28:02 UTC
Profile Built2026-09-23 01:44:24 UTC
Data FreshnessLive
Signal Types28
Total Observations53
๐Ÿ” 28 signal types ยท 53 observations collected
This report is generated from 28+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.