# INTELLIGENCE BRIEFING: IP Address 47.128.110.72
Classification: Moderate Risk / Cloud Infrastructure
Date: Current Intelligence Cycle
Prepared For: SOC Analyst Review
---
## EXECUTIVE SUMMARY
IP 47.128.110.72 is a cloud-compute instance within Amazon Web Services (AWS) infrastructure located in Singapore (ap-southeast-1). The IP carries a moderate risk score of 40/100. While the individual IP shows no active threat indicators, the associated /24 subnet demonstrates elevated abuse density (0.55), suggesting potential lateral threat activity. The IP is currently firewalled with no open services detected.
---
## TECHNICAL PROFILE
| Attribute | Value |
|---|---|
| **IP Address** | 47.128.110.72/32 |
| **Risk Score** | 40 (Moderate) |
| **ASN** | 16509 |
| **Organization** | Amazon Data Services Singapore (AMAZON-SIN) |
| **CIDR Block** | 47.128.0.0/14 |
| **Geolocation** | Singapore (1.35°N, 103.82°E) |
| **Infrastructure** | Cloud Compute (AWS EC2) |
| **Network Role** | Cloud Provider / Hosting |
---
## NETWORK CHARACTERISTICS
- DNS Resolution: ec2-47-128-110-72.ap-southeast-1.compute.amazonaws.com
- Open Ports: None detected (firewalled)
- TLS Certificates: None
- HTTP Services: None
- Connection Type: Cloud infrastructure
- Anycast/Proxy/VPN: Negative
The IP presents as a standard AWS EC2 instance with no exposed services. DNS records confirm association with the Amazon.com domain.
---
## THREAT ASSESSMENT
Direct Threat Indicators
- Blacklist Entries: 0
- Known Attacker Status: Negative
- Spam Source: Negative
- Tor Exit Node: Negative
- Active Threat Campaigns: None detected
- Abuse Confidence Score: Not applicable
Subnet Context
The /24 subnet (47.128.110.0/24) exhibits:
- Abuse Density: 0.55 (55%)
- Classification: High Abuse
- Active Siblings: 16 of 20
- Threat Siblings: 11 identified
- Inherited Risk Score: 22/100
While 19 neighboring IPs in the /24 show medium risk classifications, the subnet-level abuse density indicates this is not an isolated risk.
---
## OBSERVATION HISTORY
Total Observations: 23 signals tracked
Temporal Analysis:
- Most Recent: 2026-06-21T01:38:07 UTC
- Observation Period: Multi-day signal persistence
- Ownership Stability: No ownership changes detected
- Threat Persistence: Single threat observation recorded
- Malicious Classification: Not persistently malicious
Signal history indicates consistent cloud infrastructure classification with no sudden risk escalation. Abuse density fluctuated between 0.55-0.6 in recent observations.
---
## RELATIONSHIP GRAPH
Detected Relationships: 31 total
- DNS Associations: Multiple entries to ec2-47-128-110-72.ap-southeast-1.compute.amazonaws.com
- Network Relationships: AMAZON-SIN (Same Network)
- External Entities: No significant third-party associations identified
The IP exists primarily within AWS infrastructure boundaries with no documented relationships to external threat actors or malicious infrastructure.
---
## RECOMMENDED ACTIONS
Immediate Mitigation
The IP is classified as moderate risk with elevated neighborhood context. Consider the following:
| Platform | Recommended Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 47.128.110.72 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 47.128.110.72 drop` |
| **nginx** | `deny 47.128.110.72;` |
| **pfSense** | `47.128.110.72/32` (block entry) |
| **Cloudflare WAF** | Block expression: `ip.src eq 47.128.110.72` |
| **AWS WAF** | `Addresses: ["47.128.110.72/32"]` |
Intelligence Guidance
- Block Decision: Conditional. The moderate risk score (40) combined with high-abuse subnet context (0.55 density) warrants consideration.
- Monitor: Track for escalation in threat indicators or blacklist entries.
- Context: The /24 subnet contains 11 threat siblings. Broader subnet blocking may be warranted depending on operational risk tolerance.
- False Positive Consideration: Legitimate AWS infrastructure; verify against your organization's known AWS usage before blocking.
---
## CONCLUSION
IP 47.128.110.72 represents cloud infrastructure within AWS Singapore with no direct threat indicators. However, the elevated subnet abuse density (0.55) and presence of 11 threat-sibling IPs in the /24 network suggest potential for coordinated abuse activity. Recommend conditional blocking with monitoring for threat indicator escalation.
Priority: Medium
Action Required: Review against organizational whitelist and consider subnet-level blocking if lateral threat activity is confirmed.
---
*Intelligence generated from IPDebrief platform data. All data points sourced from automated observability signals.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | AMAZON-SIN |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-110-72.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-110-72.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-27 01:07:51 UTC |
| Last Seen | 2026-06-29 03:47:56 UTC |
| Profile Built | 2026-06-29 03:52:44 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.