# IP Intelligence Briefing: 47.128.119.128/32
## Executive Summary
IP address 47.128.119.128 is a cloud compute infrastructure asset operated by Amazon Web Services (AWS) Singapore. The IP carries a moderate risk score of 50 and belongs to a high-abuse density subnet (47.128.119.0/24) with an abuse density rating of 0.5895. No active threat indicators were identified for this specific address, though the neighborhood exhibits elevated risk.
## Technical Profile
- Organization: Amazon Data Services Singapore (AMAZON-SIN)
- ASN: 16509 (Amazon.com Inc.)
- CIDR Block: 47.128.0.0/14
- Geolocation: Singapore (ap-southeast-1 region)
- Infrastructure Type: Cloud Compute / Hosting
- DNS Resolution: ec2-47-128-119-128.ap-southeast-1.compute.amazonaws.com (forward confirmed)
- Services: Firewalled / No services detected on open ports
## Threat Assessment
- Risk Score: 50 (Moderate Risk)
- Blacklist Status: 0 blacklists
- DNSBL Listed: 2 of 8 threat feeds
- Threat Classifications: Not a known attacker, not a spam source, not a Tor exit node, not a proxy
- Campaign Correlation: No known campaign matches or banner matches
## Neighborhood Analysis
The IP resides in subnet 47.128.119.0/24, which shows elevated abuse characteristics:
- Total Subnet Siblings: 95 IPs
- Active Siblings: 70
- Threat Siblings: 56
- Abuse Density Classification: High abuse (0.5895)
- Risk Distribution: 30 medium risk, 67 low risk, 0 high risk
This indicates the subnet is commonly used for legitimate AWS infrastructure but contains a significant portion of suspicious activity, typical of cloud hosting environments.
## Historical Observations
Analysis of 22 signal observations reveals:
- Provider Consistency: Consistent classification as AWS cloud infrastructure
- Geolocation Variance: One observation (0.35 confidence) suggested US location; primary consensus remains Singapore
- Operator Score: 0.2609 (Basic classification)
- Threat Persistence: 0 days flagged as persistently malicious
- Observation Timeline: Signals observed from June 2026, with consistent infrastructure classification
## Recommended Actions
Based on the moderate risk profile and neighborhood context, the following firewall rules are recommended:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 47.128.119.128 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 47.128.119.128 drop` |
| nginx | `deny 47.128.119.128;` |
| pfSense | `47.128.119.128/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 47.128.119.128` |
| AWS WAF | Add `47.128.119.128/32` to block list |
## Intelligence Notes
This IP should be evaluated in context of the broader subnet abuse density. While the specific address shows no active threat indicators, the neighborhood classification warrants consideration in security policy decisions. The absence of open services suggests this may be a backend infrastructure component or recently provisioned instance. SOC analysts should monitor for any emergence of threat indicators or behavioral changes in this address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | AMAZON-SIN |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-119-128.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-119-128.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 46% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 28% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-25 00:41:31 UTC |
| Last Seen | 2026-06-29 01:01:16 UTC |
| Profile Built | 2026-06-29 07:04:26 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.