IPDebrief

54.76.74.206

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence Briefing: 54.76.74.206/32

Infrastructure Ownership:

Analysis identified the IP as infrastructure belonging to Amazon Technologies Inc. (ASN 16509) within the AMAZON-2011L block (54.64.0.0/11). DNS resolution confirmed the address as an EC2 instance located in Dublin, Ireland.

Service Configuration:

The endpoint operated HTTP and HTTPS services on ports 80 and 443. TLS certificate analysis revealed a subject for `*.push.samsungosp.com`, associated with Samsung Electronics Co,.LTD in Gyeonggi-do, KR. The certificate issuer is Sectigo RSA Organization Validation Secure Server CA.

Threat and Risk Profile:

The asset held a Low Risk reputation score of 25. Behavioral monitoring recorded zero honeypot hits and zero WAF violations. However, the address appeared on one DNSBL out of eight queried lists. Control plane data flagged the host as a "Suspicious Host" due to signal contradictions, though it was not classified as a known attacker.

Data Contradictions:

Geolocation validation failed consensus. While primary sources located the server in Ireland (IE), the TLS certificate and secondary sources indicated South Korea (KR). Geo sources disagreed on country, and the certificate subject location did not match the primary server location.

Recommendation:

Security operations teams should monitor the address. While the IP represents a legitimate cloud hosting provider, conflicting geolocation signals and minor blacklist presence suggest a need for continued observation until signal coherence improves.

Observation Window:

Activity was recorded between 2026-08-29 and 2026-09-06.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡ช Ireland
RegionD
CityDublin
TimezoneEurope/Dublin
Latitude53.35
Longitude-6.26

๐Ÿข Ownership & Registration

OrganizationAmazon Technologies Inc.
ASNAS16509
Network NameAMAZON-2011L
CIDR Block54.64.0.0/11
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRec2-54-76-74-206.eu-west-1.compute.amazonaws.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesec2-54-76-74-206.eu-west-1.compute.amazonaws.com

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPF4/4 domains
DMARC2/4 domains
FCrDNSVerified
DNSSECNot signed
CAANot configured
Domains Checked4 domains

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=*.push.samsungosp.com, O="SAMSUNG ELECTRONICS CO,.LTD", S=Gyeonggi-do, C=KR
Issued by CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
Self-signed: No
SANs*.push.samsungosp.compush.samsungosp.com
Valid From2025-11-17T00:00:00+00:00
Valid Until2026-12-18T23:59:59+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
Signature Algorithmsha256RSA
Validity Period396 days
Serial Number163F914E35AFA5204EAE5DC0D06733D3
Thumbprint1565E26D89D47C1A2980DCF56D0FCD39AC1E4E91

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
24
routing
13%
11
services
33%
24
ownership
27%
23
reputation
13%
12
geolocation
27%
23
Overall24%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) โ€” 2 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: GB, KR, IE
โš  TLS certificate claims KR but primary geo says IE

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-08-29 21:19:07 UTC
Last Seen2026-09-23 05:12:23 UTC
Profile Built2026-09-23 05:22:51 UTC
Data FreshnessLive
Signal Types27
Total Observations39
๐Ÿ” 27 signal types ยท 39 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.