IPDebrief

47.128.112.238

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 47.128.112.238

Date: 2026-06-11

---

**1. Core Profile**

- Country: United States (US)

- Region: Illinois (US-IL)

- City: Chicago

- Timezone: America/Chicago

- Type: Cloud Compute (AWS infrastructure)

- Classification: Firewalled / No Services

- Subnet: 47.128.112.238/24 (High Abuse Density: 69%)

---

**2. Threat Indicators**

- Linked to AWS EC2 hostname: `ec2-47-128-112-238.ap-southeast-1.compute.amazonaws.com`.

- Abuse Density: 69% (high risk).

- Threat Siblings: 69 IPs in the subnet show malicious activity.

---

**3. Historical Observations**

- Conflicting data shows the IP resolving to Singapore (latitude: 1.2872, longitude: 103.8507) despite AWS ownership.

- Subnet route stability: Unstable (route changes detected).

- No persistent malicious activity over 30 days.

---

**4. Relationships**

- Same network as AMAZON-SIN (AWS).

- Direct association with AWS EC2 instances.

---

**5. Neighborhood Analysis**

- 100 total IPs in subnet; 59 active, 69 flagged as malicious.

- Risk Distribution: 88 medium-risk IPs, 11 low-risk IPs.

---

**6. Recommended Actions**

- Investigate geolocation discrepancies (potential misattribution or spoofing).

- Monitor subnet for anomalous traffic due to high abuse density.

- iptables: `iptables -A INPUT -s 47.128.112.238 -j DROP`

- Cloudflare WAF: Block IP with rule: `ip.src eq 47.128.112.238`

- AWS WAF: Add rule: `47.128.112.238/32`

---

Conclusion:

The IP is part of AWS infrastructure and appears legitimate. However, its subnet (47.128.112.238/24) has a high abuse density, suggesting potential risks. While the IP itself shows no direct malicious activity, the network environment warrants further investigation. SOC teams should prioritize monitoring this subnet for suspicious behavior and validate geolocation inconsistencies.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
RegionSG
CitySingapore
TimezoneAsia/Singapore
Latitude1.35
Longitude103.82

🏒 Ownership & Registration

OrganizationAmazon Data Services Singapore
ASNAS16509
Network NameAMAZON-SIN
CIDR Block47.128.0.0/14
RIRARIN
CountrySingapore
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-47-128-112-238.ap-southeast-1.compute.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesec2-47-128-112-238.ap-southeast-1.compute.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
19%
22
routing
13%
11
services
13%
11
ownership
27%
23
reputation
13%
12
geolocation
19%
22
Overall17%911
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-28 18:35:07 UTC
Last Seen2026-06-29 05:52:02 UTC
Profile Built2026-06-29 05:52:57 UTC
Data FreshnessLive
Signal Types20
Total Observations23
πŸ” 20 signal types Β· 23 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.