# IP Intelligence Briefing: 47.128.119.126/32
## Executive Summary
Target 47.128.119.126 is a cloud-compute IP address (AWS EC2) hosted in Singapore (ap-southeast-1). The IP carries a moderate risk score of 40/100 with no active threat indicators. However, the /24 subnet (47.128.119.0/24) exhibits elevated abuse density (0.6966) with 62 threat siblings out of 89 active neighbors.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 47.128.119.126/32 |
| **Risk Score** | 40 (Moderate Risk) |
| **Provider** | Amazon Web Services (ASN: 16509) |
| **Organization** | Amazon Data Services Singapore |
| **Location** | Singapore (1.35°N, 103.82°E) |
| **Infrastructure Type** | CloudCompute / Hosting |
| **DNS Resolution** | ec2-47-128-119-126.ap-southeast-1.compute.amazonaws.com |
| **Services** | Firewalled / No Open Ports |
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 (Profile shows 0; Control plane shows 1 DNSBL listing out of 8 total lists)
- Campaign Activity: None detected
- Threat Feeds: No matches
## Neighborhood Analysis (47.128.119.0/24)
- Total Neighbors: 94
- Active Siblings: 66
- Threat Siblings: 62
- Abuse Density: 0.6966 (High Abuse classification)
- Inherited Risk: 27
Risk distribution across subnet: 0 high-risk, 88 medium-risk, 6 low-risk IPs. The subnet demonstrates concentrated abuse activity, though the target IP itself shows no active threat indicators.
## Observation History
23 signal observations recorded since 2026-06-15. Consistent classification as AWS cloud infrastructure with stable ownership. No evidence of persistently malicious behavior. Geo-location validated as plausible (Singapore) with distance calculation of 10,382.9 km from probe origin.
## Recommended Actions
Given the elevated neighborhood abuse density, defensive blocking is recommended despite the target IP's clean threat profile:
Firewall Rules:
- iptables: `iptables -A INPUT -s 47.128.119.126 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 47.128.119.126 drop`
- nginx: `deny 47.128.119.126;`
- pfSense: `47.128.119.126/32`
- Cloudflare WAF: Block with expression `ip.src eq 47.128.119.126`
- AWS WAF: Add to block list `47.128.119.126/32`
Rationale: While the IP shows no active malicious indicators, the high-abuse subnet context suggests potential for future abuse or compromised adjacent infrastructure. Implementing block rules provides layered defense against potential lateral movement or abuse from related IP addresses.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-119-126.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Hosted Domain | ec2-47-128-119-126.ap-southeast-1.compute.amazonaws.com |
| Forward Hostnames | ec2-47-128-119-126.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 44% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-23 06:22:49 UTC |
| Last Seen | 2026-06-28 20:40:25 UTC |
| Profile Built | 2026-06-29 02:43:09 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.