IP Address

3.131.220.121

IPv4 Public
US US
AS16509
AMAZON-02
2,225 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
8/10 Threat
86% Confidence
2,225 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
US
US Location
AMAZON-02 ASN 16509
2,225 Reports
Honeypot Data Source

Substantial Risk

IP 3.131.220.121 is a high-risk address operated within the AMAZON-02 autonomous system (AS16509) that has generated 1,596 abuse reports across automated honeypot sensors with a threat level of 8 out of 10, indicating sustained and aggressive malicious activity originating from a US-based cloud infrastructure provider.

The IP was first reported in February 2026 and most recently in July 2026, representing a six-month window of continuous hostile probing activity with an activity frequency score of 8 out of 10. Detection data from 20 separate honeypot sensors documents a diverse attack profile dominated by general hacking intrusion attempts (18 recent reports), supplemented by IoT-targeted probes (2 reports) and web application reconnaissance (1 report). The high volume of total reports combined with an 85% confidence score suggests this is not an isolated incident or misconfiguration but rather systematic, automated exploitation activity being conducted from Amazon Web Services infrastructure.

The dominant hacking category encompasses broad unauthorized access attempts, vulnerability scanning, and exploitation probing against exposed services. This pattern poses concrete risk to any publicly accessible systems, as the volume of reports indicates persistent automated scanning rather than a single targeted attack. The secondary IoT-targeted activity suggests the address is also being used to scout for poorly secured connected devices, while the web application probe indicates interest in application-layer vulnerabilities. The geographic origin within US cloud infrastructure is notable because many defensive systems apply geographic exception rules that may inadvertently whitelist traffic from major US cloud providers, potentially allowing this malicious traffic to bypass basic geographic filtering.

Site operators should implement immediate defensive measures including blocking or rate-limiting this address at the firewall level, deploying fail2ban or similar dynamic blocking tools to automatically respond to repeated connection attempts, and reviewing public-facing services for unnecessary exposure. Network segmentation of IoT devices and deployment of a web application firewall would specifically address the secondary threat categories observed. Regular security audits and prompt patching of vulnerabilities remain essential given the ongoing scanning activity documented across the six-month reporting window.

More threatening than 91% of monitored IPs

Threat Categories

Hacking 29
Exploited Host 1

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Behavioral Analysis

Activity Pattern: Sporadic

Irregular burst activity pattern indicates intermittent use of a compromised system.

First Observed 31. July 2026
Last Activity 29. August 2026
Recent (7 days) 111 incidents

Cloud Infrastructure

This IP operates from Amazon Web Services (AWS) cloud infrastructure. Cloud-hosted threats can be provisioned and abandoned quickly, affecting attribution.

Cloud-hosted malicious activity often indicates automated or scalable attack infrastructure.

Security Recommendations

Implement adaptive blocking rules.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 8/10 High
Confidence Score 86% Verified

Confidence History

28. Aug 2026 - 29. Aug 2026
86% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Hacking Honeypot 75%
New Exploited Host Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%

Technical Details

Basic Information

IP Address
3.131.220.121
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
US US
ASN
AS16509
ISP
AMAZON-02

DNS Information

Reverse DNS
scan.visionheight.com
PTR Record
Yes
Connection Type
Static

Statistics

Total Reports
2,225
First Reported
10 Feb 2026
Last Reported
29 Aug 2026, 10:16

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS16509
Amazon.com, Inc.
US US

Network Threat Assessment

4/10
This network has low threat indicators with minimal suspicious activity.

Network Statistics

3,313
Total IPs Monitored
133,751
Total Reports
40.4
Reports per IP

Network Context

This IP address belongs to Amazon.com, Inc. (AS16509), which manages 3,313 IP addresses in our monitoring system. Out of these, 133,751 have been reported for suspicious activities, resulting in a network-wide threat level of 4/10.

Network notice: This network shows some suspicious activity patterns. Monitor interactions with IPs from this ASN.

Comparative Analysis

How this IP compares to others in our threat intelligence database

91 %

Global Threat Ranking

This IP is more threatening than 91% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 654,294 reported IPs worldwide

Threat Level 8/10 avg: 5.7 +
Total Reports 2,225 avg: 10 ++

Network Comparison

Compared against 7,285 IPs in ASN 16509

Threat Level 8/10 network avg: 6.0 +
Total Reports 2,225 network avg: 21 ++
Network AMAZON-02 has overall threat level 4/10

Geographic Comparison

Compared against 111,356 IPs in US

Threat Level 8/10 country avg: 6.3 +
Total Reports 2,225 country avg: 21 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

552,660 threat incidents tracked globally • Last 24h: 98,725 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    111,356 20.1%
  2. 02
    BR
    Brazil BR
    100,834 18.2%
  3. 03
    IN
    India IN
    59,735 10.8%
  4. 04
    CN
    China CN
    39,359 7.1%
  5. 05
    AR
    Argentina AR
    14,173 2.6%
  6. 06
    CO
    Colombia CO
    14,130 2.6%
  7. 07
    DE
    Germany DE
    12,484 2.3%
  8. 08
    PK
    Pakistan PK
    10,813 2%
  9. 09
    RU
    Russia RU
    10,553 1.9%
  10. 10
    ID
    Indonesia ID
    10,015 1.8%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
8.9/10 Avg Threat
98% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "3.131.220.121",
    "threat_level": 8,
    "confidence_score": 86,
    "total_reports": 2225,
    "country_code": "US",
    "isp_name": "AMAZON-02",
    "asn": "16509",
    "first_reported": "2026-02-10 05:28:25",
    "last_reported": "2026-08-29 10:16:46",
    "exported_at": "2026-08-29T11:15:49+02:00",
    "source": "https://reportedip.com/ip/3.131.220.121/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.