IP Intelligence Briefing: 47.128.119.160
Date: 2026-06-09
---
**1. Core Profile**
- Reputation: Moderate Risk (Risk Score: 40)
- Ownership: Amazon Data Services Singapore (ASN: 16509)
- Geolocation: Singapore (1.35°N, 103.82°E), Asia/Singapore timezone
- Network Role: AWS EC2 instance (Firewalled / No Services)
- Threat Indicators: No malicious activity detected (zero indicators, no blacklists, no campaigns).
---
**2. Network Context**
- Subnet: 47.128.119.160/24
- Abuse Density: 55.84% (High Abuse classification)
- Neighboring IPs:
- 69 IPs flagged as medium-risk (avg. score: 40)
- 15 IPs flagged as low-risk
- 43 IPs in subnet linked to threats (potential lateral movement risk)
- Subnet Owner: AMAZON-SIN (AWS Singapore region)
---
**3. Observations & Behavior**
- Historical Signals:
- 22 observations over 30 days (last updated 2026-06-09).
- Mixed confidence levels (0.21β0.95), with 17% of signals indicating "high_abuse" classification.
- No persistent malicious activity (threat persistence: 0 days).
- DNS Associations:
- Linked to AWS EC2 hostname: `ec2-47-128-119-160.ap-southeast-1.compute.amazonaws.com`
- Valid DNSSEC, SPF, and DMARC records.
---
**4. Threat & Security Implications**
- No Direct Threat: The IP itself shows no malicious indicators (zero blacklists, no campaigns, no spam).
- Subnet Risk: High abuse density in the 47.128.119.160/24 subnet suggests potential for lateral movement or shared infrastructure risks.
- Actionable Steps:
- Monitor subnet for unusual activity (e.g., unexpected DNS changes, port scanning).
- Consider blocking the entire 47.128.119.160/24 subnet if isolating AWS resources.
- Validate DNS records and ensure AWS security groups are properly configured.
---
**5. Summary**
The IP is a legitimate AWS EC2 instance with no direct malicious activity. However, its subnet exhibits high abuse density, warranting closer scrutiny. SOC teams should focus on monitoring the subnet for anomalous behavior and ensure proper segmentation of cloud resources.
Recommended Tools: Use AWS WAF to block the subnet, and correlate with neighbor IPs for deeper analysis.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-119-160.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-119-160.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 6 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-20 05:44:59 UTC |
| Last Seen | 2026-06-28 11:15:27 UTC |
| Profile Built | 2026-06-29 05:20:04 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.