# IP Intelligence Briefing: 47.128.112.247/32
Classification: Moderate Risk
Date: Current
Status: Active Monitoring Recommended
## Executive Summary
IP address 47.128.112.247 is an Amazon Web Services (AWS) EC2 instance hosted in the Singapore region (ap-southeast-1). The IP carries a moderate risk score of 40, primarily attributable to high abuse density within its /24 subnet. No direct threat indicators or malicious activity were observed on the target IP.
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 47.128.112.247/32 |
| **Organization** | Amazon Data Services Singapore |
| **ASN** | 16509 |
| **Country** | Singapore (SG) |
| **Region** | Asia Pacific (Singapore) |
| **Infrastructure Type** | Cloud Compute (AWS EC2) |
| **Risk Score** | 40 / 100 |
| **Abuse Confidence** | Not scored |
## Network Environment
The target IP resides within the 47.128.112.0/24 subnet, classified as high_abuse. Neighborhood analysis reveals:
- Total Siblings: 100 IPs
- Active Siblings: 81
- Threat Siblings: 69
- Abuse Density: 0.69 (69%)
- Inherited Risk Score: 27
All neighboring IPs in the subnet exhibit uniform risk scoring (40) with authority scores of 60, indicating this is a legitimate AWS data center block rather than a compromised subnet.
## Threat Indicators
Observed Malicious Activity: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Threat Feeds: No matches
DNS Analysis:
- PTR Record: ec2-47-128-112-247.ap-southeast-1.compute.amazonaws.com
- Forward Resolution: Confirmed (amazonaws.com)
- Email Auth: SPF and DMARC records present
Services: No open ports detected. The instance is either properly hardened or running with firewall restrictions.
## Historical Observations
Signal history indicates consistent classification over the observation period. Recent signals (June 25, 2026 timeframe) confirm:
- Stable geolocation reporting (Singapore)
- Consistent cloud infrastructure classification
- Persistent high_abuse subnet classification
- No ownership changes detected
## Relationship Mapping
The IP is associated with the following entities:
- Network: AMAZON-SIN (Singapore AWS network)
- Hostname: ec2-47-128-112-247.ap-southeast-1.compute.amazonaws.com
- Network Block: 47.128.0.0/14
## Recommended Actions
Given the moderate risk score and high-abuse neighborhood context, the following recommendations apply:
Default Stance
Monitor β No immediate blocking required. The IP shows no direct malicious activity.
Firewall Rules (If Blocking Required)
```
iptables: iptables -A INPUT -s 47.128.112.247 -j DROP
nftables: nft add rule inet filter input ip saddr 47.128.112.247 drop
nginx: deny 47.128.112.247;
```
Cloud Platform Recommendations
- Cloudflare WAF: Block with expression `ip.src eq 47.128.112.247`
- AWS WAF: Block CIDR `47.128.112.247/32` with description "IPDebrief risk 40"
Operational Notes
1. Do not block based on risk score alone β This is an AWS EC2 instance with legitimate cloud infrastructure purpose
2. Monitor for anomalous behavior β While the IP itself shows no malicious signals, the high-abuse neighborhood warrants baseline traffic monitoring
3. Consider contextual analysis β If traffic from this IP is observed, evaluate against organizational baselines before taking action
## Conclusion
IP 47.128.112.247 is a legitimate AWS infrastructure asset in Singapore with moderate risk scoring driven by neighborhood abuse density. No immediate threat indicators were identified. Recommend monitoring rather than blocking, and evaluate any observed traffic against organizational security policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-112-247.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-112-247.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 21% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-08 17:18:06 UTC |
| Last Seen | 2026-06-27 13:56:05 UTC |
| Profile Built | 2026-06-28 08:01:17 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.