IP Address

18.116.101.220

IPv4 Public
US US
AS16509
AMAZON-02
3,495 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
8/10 Threat
90% Confidence
3,495 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
US
US Location
AMAZON-02 ASN 16509
3,495 Reports
Honeypot Data Source

Significant Threat

IP 18.116.101.220 is a high-risk address operating from Amazon Web Services infrastructure (AS16509, AMAZON-02) that has generated 3,470 abuse reports between February and August 2026, indicating sustained malicious activity dominated by hacking intrusion attempts detected across 20 automated honeypot sensors with a threat level rating of 8 out of 10.

The report volume for this United States-based IP address is substantial, with an activity frequency rated at 8 out of 10, suggesting persistent scanning and exploitation behaviour over a seven-month window. Analysis of the most recent 22 reports categorises the threat profile as primarily hacking activity (19 reports), complemented by two exploited host indicators and one IoT-targeted report. The detected attack patterns include general attack connections, malware and exploit activity, and specifically a Suricata alert flagging application-layer protocol detection occurring in only one communication direction. These patterns align with automated exploitation toolkits and reconnaissance probes commonly associated with credential guessing, vulnerability scanning, and post-compromise payload delivery attempts.

Hacking activity as the dominant threat category encompasses unauthorised access attempts, vulnerability exploitation, and intrusion probes that target exposed services running on internet-facing systems. The presence of malware and exploit-related patterns suggests this address may be utilised to deliver or execute malicious payloads. The exploited host signals raise the possibility that the IP address itself, or systems operating within this AWS allocation, may have been compromised and are being weaponised without the operator's knowledge to conduct secondary attacks. IoT targeting activity, though minimal in recent reports, indicates potential interest in smart devices, cameras, or industrial control systems with weak security configurations.

Site operators should block or rate-limit connections from 18.116.101.220 at the network perimeter, implement strong authentication mechanisms on all exposed services, and deploy intrusion detection systems to monitor for the observed attack patterns. Keeping systems patched and following security best practices significantly reduces vulnerability to the exploitation techniques this address employs. Deploying defensive tools such as fail2ban can automate blocking responses to repeated connection attempts characteristic of brute-force activity. Network segmentation of IoT devices and disabling unnecessary protocols limits the attack surface available to this threat actor.

More threatening than 84% of monitored IPs

Threat Categories

Hacking 29
IoT Targeted 2
Email Spam 1
Port Scan 1

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Behavioral Analysis

Activity Pattern: Sporadic

Irregular burst activity pattern indicates intermittent use of a compromised system.

First Observed 8. July 2026
Last Activity 6. August 2026
Recent (7 days) 202 incidents

Cloud Infrastructure

This IP operates from Amazon Web Services (AWS) cloud infrastructure. Cloud-hosted threats can be provisioned and abandoned quickly, affecting attribution.

Cloud-hosted malicious activity often indicates automated or scalable attack infrastructure.

Security Recommendations

Implement adaptive blocking rules.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 8/10 High
Confidence Score 90% Verified

Confidence History

5. Aug 2026 - 6. Aug 2026
90% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
New Hacking Honeypot 75%
New Hacking Email Spam IoT Targeted Honeypot x3 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Port Scan Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New IoT Targeted Hacking Honeypot x2 75%
New Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%

Technical Details

Basic Information

IP Address
18.116.101.220
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
US US
ASN
AS16509
ISP
AMAZON-02

DNS Information

Reverse DNS
scan.visionheight.com
PTR Record
Yes
Connection Type
Static

Statistics

Total Reports
3,495
First Reported
10 Feb 2026
Last Reported
6 Aug 2026, 15:49

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS16509
Amazon.com, Inc.
US US

Network Threat Assessment

4/10
This network has low threat indicators with minimal suspicious activity.

Network Statistics

3,313
Total IPs Monitored
133,751
Total Reports
40.4
Reports per IP

Network Context

This IP address belongs to Amazon.com, Inc. (AS16509), which manages 3,313 IP addresses in our monitoring system. Out of these, 133,751 have been reported for suspicious activities, resulting in a network-wide threat level of 4/10.

Network notice: This network shows some suspicious activity patterns. Monitor interactions with IPs from this ASN.

Comparative Analysis

How this IP compares to others in our threat intelligence database

84 %

Global Threat Ranking

This IP is more threatening than 84% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 312,072 reported IPs worldwide

Threat Level 8/10 avg: 6.0 +
Total Reports 3,495 avg: 18 ++

Network Comparison

Compared against 6,329 IPs in ASN 16509

Threat Level 8/10 network avg: 5.8 +
Total Reports 3,495 network avg: 23 ++
Network AMAZON-02 has overall threat level 4/10

Geographic Comparison

Compared against 65,785 IPs in US

Threat Level 8/10 country avg: 6.5 +
Total Reports 3,495 country avg: 31 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

292,633 threat incidents tracked globally • Last 24h: 17,619 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    65,774 22.5%
  2. 02
    IN
    India IN
    49,098 16.8%
  3. 03
    CN
    China CN
    35,622 12.2%
  4. 04
    BR
    Brazil BR
    15,554 5.3%
  5. 05
    DE
    Germany DE
    10,499 3.6%
  6. 06
    PK
    Pakistan PK
    8,474 2.9%
  7. 07
    ID
    Indonesia ID
    8,403 2.9%
  8. 08
    SG
    Singapore SG
    8,312 2.8%
  9. 09
    RU
    Russia RU
    6,393 2.2%
  10. 10
    NL
    Netherlands NL
    6,295 2.2%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9/10 Avg Threat
97% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "18.116.101.220",
    "threat_level": 8,
    "confidence_score": 90,
    "total_reports": 3495,
    "country_code": "US",
    "isp_name": "AMAZON-02",
    "asn": "16509",
    "first_reported": "2026-02-10 05:18:13",
    "last_reported": "2026-08-06 15:49:30",
    "exported_at": "2026-08-06T15:54:19+02:00",
    "source": "https://reportedip.com/ip/18.116.101.220/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.