# IP Intelligence Briefing: 47.128.112.217/32
## Executive Summary
IP 47.128.112.217 is an AWS EC2 instance deployed in Singapore (ap-southeast-1). The IP exhibits moderate risk characteristics with a risk score of 40. While the IP itself shows no active threat indicators, it resides within a high-abuse-density subnet (47.128.112.0/24), which warrants contextual awareness for threat hunting operations.
## Infrastructure Profile
- ISP/Provider: Amazon Web Services (ASN 16509)
- Organization: Amazon Data Services Singapore
- Geolocation: Singapore (1.35°N, 103.82°E)
- DNS Resolution: ec2-47-128-112-217.ap-southeast-1.compute.amazonaws.com
- Infrastructure Type: CloudCompute / Hosting
- Service Status: Firewalled / No Services Open
- Email Authentication: SPF and DMARC records present for associated domain
## Threat Assessment
- Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not assessed
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- DNSBL Listings: 1 listing across 8 total lists
## Neighborhood Analysis
The IP operates within subnet 47.128.112.0/24, which demonstrates elevated abuse density:
- Subnet Classification: High Abuse
- Total Siblings: 100
- Active Siblings: 79
- Threat-Sensitive Siblings: 71
- Risk Distribution: 0 high-risk, 97 medium-risk, 2 low-risk
The majority of sibling IPs in the subnet maintain a risk score of 40 with authority scores of 60, indicating consistent infrastructure patterns typical of cloud hosting environments.
## Historical Observations
Analysis of 22 signal observations reveals:
- Geolocation Consistency: Persistent Singapore location across all observations
- Ownership Stability: No ownership changes detected
- Threat Persistence: Not flagged as persistently malicious
- Operator Classification: Basic (score: 0.2609)
- Route Stability: Route changes observed over 30-day period; not considered stable
## SOC Actions & Recommendations
Immediate Actions
1. Allow with Monitoring: The IP is a legitimate AWS infrastructure endpoint. No immediate blocking recommended.
2. Traffic Analysis: Monitor for anomalous outbound connections from this IP, particularly if it begins exhibiting behavior inconsistent with cloud infrastructure.
3. Subnet Context: Be aware that 71% of sibling IPs in the /24 subnet have been flagged as threats. Correlate any suspicious activity with this contextual risk.
Rule Recommendations
- No firewall rules required for this specific IP.
- Consider implementing egress filtering on internal networks that reference this subnet.
- Add to monitoring dashboards for correlation with threat indicators from the 47.128.112.0/24 subnet.
Intelligence Notes
This IP represents a standard AWS cloud compute resource. The elevated neighborhood risk score reflects the high-abuse environment of the Singapore AWS region rather than malicious activity on this specific endpoint. Maintain awareness of sibling IPs during threat hunting operations in this subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-112-217.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-112-217.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-14 07:14:45 UTC |
| Last Seen | 2026-06-28 00:33:07 UTC |
| Profile Built | 2026-06-28 18:38:10 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.