IP INTELLIGENCE BRIEFING: 47.128.115.24
Classification: LOW RISK / INFRASTRUCTURE
Date of Assessment: Current
Assigned Risk Score: 25/100
---
EXECUTIVE SUMMARY
IP address 47.128.115.24 is identified as a legitimate Amazon Web Services (AWS) cloud compute resource located in Singapore. The IP exhibits low-risk characteristics with no active threat indicators, no open services, and minimal malicious activity. The address is part of AWS infrastructure (AP-Southeast-1 region) and shows consistent operational behavior over the observation period.
---
OWNERSHIP AND GEOLOCATION
- Organization: Amazon Data Services Singapore
- ASN: 16509 (Amazon.com)
- Network Block: 47.128.0.0/14
- Location: Singapore (1.35°N, 103.82°E)
- Geolocation Confidence: High (validated via multiple sources)
- Infrastructure Type: Cloud Compute / Hosting
- Network Role: Firewalled / No Services Exposed
---
THREAT INDICATORS
Threat Status: CLEAN
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Abuse Confidence Score: Not applicable (cloud infrastructure)
- DNSBL Listings: 1 of 8 checks (likely benign cloud provider listing)
Threat History: No persistent malicious activity detected. Zero threat observation count with no campaign correlations.
---
NETWORK CONTEXT AND NEIGHBORHOOD ANALYSIS
The IP resides within subnet 47.128.115.0/24 containing 34 sibling addresses:
- Abuse Density: 0.4706 (moderate for cloud subnet)
- Risk Distribution: 0 high-risk, 8 medium-risk, 26 low-risk neighbors
- Inherited Risk Score: 18/100
- Subnet Classification: Mixed (cloud infrastructure environment)
Neighboring IPs show typical AWS EC2 risk profiles with most addresses maintaining risk scores between 0-40, consistent with legitimate cloud hosting operations.
---
DNS AND SERVICE FINGERPRINT
- PTR Record: ec2-47-128-115-24.ap-southeast-1.compute.amazonaws.com
- Forward Resolution: Confirmed (1 hostname)
- Open Ports: None detected
- HTTP/S Services: None detected
- TLS Certificates: None
- Email Authentication: SPF and DMARC records present on associated domain
---
OBSERVATION HISTORY
The IP has been monitored across 24 observations. Key findings:
- Temporal Stability: Consistent classification as cloud infrastructure
- Operator Score: 0.2609 (Basic level)
- Route Stability: Not stable (typical for cloud ephemeral resources)
- Geo Validation: Plausible location confirmed; ICMP validation blocked (expected for cloud infrastructure)
- Ownership Changes: None detected
- Threat Persistence Days: 0
---
SECURITY RECOMMENDATIONS
Immediate Action: Monitor as legitimate cloud infrastructure
- No blocking required. The IP represents standard AWS infrastructure.
- No firewall rules recommended at this time.
- Continue standard monitoring for any behavioral changes.
Contextual Notes:
- This IP is part of the AMAZON-SIN network and associated with legitimate AWS Singapore region services.
- The absence of open ports and services indicates this is likely a backend or internal-facing resource.
- Any unexpected activity from this IP would warrant investigation against baseline cloud infrastructure behavior.
---
Analyst Notes: This IP address represents routine AWS cloud infrastructure with no malicious indicators. Standard cloud provider attribution applies. No threat mitigation actions required at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-115-24.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-115-24.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:23 UTC |
| Last Seen | 2026-06-27 05:47:52 UTC |
| Profile Built | 2026-06-27 23:53:27 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.