# INTELLIGENCE BRIEFING: 47.128.112.25
Classification: MODERATE RISK / CLOUD INFRASTRUCTURE
Date of Analysis: Current
Risk Score: 40/100
## EXECUTIVE SUMMARY
IP 47.128.112.25 is a cloud compute resource hosted by Amazon Web Services in Singapore. The address resolves to a legitimate AWS EC2 instance (ec2-47-128-112-25.ap-southeast-1.compute.amazonaws.com) with no open services detected. While the individual IP shows no direct threat indicators, the address belongs to a high-abuse-density subnet requiring defensive monitoring.
## INFRASTRUCTURE PROFILE
- Owner: Amazon Data Services Singapore (ASN 16509)
- Location: Singapore (SG)
- Classification: CloudCompute / Hosted Infrastructure
- DNS Resolution: ec2-47-128-112-25.ap-southeast-1.compute.amazonaws.com
- Email Auth: SPF and DMARC records present
- Services: No open ports detected; service purpose marked as "Firewalled / No Services"
- Network Role: AWS EC2 instance in ap-southeast-1 region
## THREAT ASSESSMENT
- Risk Score: 40 (Moderate Risk)
- Threat Indicators: None detected
- Blacklist Status: 0 blacklist hits
- Campaign Affiliation: None identified
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
## NEIGHBORHOOD ANALYSIS
The /24 subnet (47.128.112.25/24) exhibits concerning abuse characteristics:
- Abuse Density: 0.75 (High)
- Total Siblings: 100
- Active Siblings: 72
- Threat Siblings: 75
- Inherited Risk: 30
The subnet contains 99 neighbors with a risk distribution of 97 medium-risk and 2 low-risk addresses. Multiple IPs in the range (e.g., 47.128.112.2, 47.128.112.3, 47.128.112.4, 47.128.112.5, 47.128.112.20) share the same risk profile.
## OBSERVATION HISTORY
IPDebrief recorded 22 observations over the monitoring period. The most recent signals indicate:
- Operator score: 0.2609 (Basic classification)
- DNSSEC validation: Enabled
- Control plane stability: Route changes noted in last 30 days
- Threat persistence: No persistent malicious activity detected
## RELATIONSHIP GRAPH
- DNS Associations: Multiple entries for ec2-47-128-112-25.ap-southeast-1.compute.amazonaws.com
- Network Affiliation: AMAZON-SIN network
- Total Relationships: 44 detected
## RECOMMENDED ACTIONS
Despite the moderate individual risk score, the high neighborhood abuse density warrants defensive posture:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 47.128.112.25 -j DROP
# nftables
nft add rule inet filter input ip saddr 47.128.112.25 drop
# pfSense
47.128.112.25/32
```
Cloud WAF Integration:
- Cloudflare WAF: Block with expression `ip.src eq 47.128.112.25`
- AWS WAF: Add 47.128.112.25/32 to block list with description "IPDebrief risk 40"
## INTELLIGENCE JUDGMENT
This IP represents cloud infrastructure in a high-abuse AWS subnet. The combination of moderate individual risk (40) and high neighborhood abuse density (0.75) suggests potential for compromise or abuse of shared cloud resources. SOC teams should monitor for outbound connections from this IP and consider blocking inbound traffic. The address maintains a legitimate AWS hostname and proper DNS configuration, indicating it may be a shared IP pool rather than a dedicated compromised host.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-112-25.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-112-25.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-13 12:13:28 UTC |
| Last Seen | 2026-06-27 23:24:46 UTC |
| Profile Built | 2026-06-28 17:30:13 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.