Threat Intelligence Briefing: IP Address 47.128.119.181/32
Summary:
The IP address 47.128.119.181/32 is associated with Amazon Data Services Singapore (ASN 16509) and is registered to Amazon Web Services (AWS). It is geolocated in Singapore and classified as a cloud compute infrastructure node. While the IP itself is rated Low Risk (risk score: 25), its subnet (47.128.119.181/24) contains a mix of low/medium-risk IPs, with 68% of neighbors classified as medium risk.
Key Findings:
1. Network Context:
- Hosted on AWS, likely an EC2 instance (DNS records point to `ec2-47-128-119-181.ap-southeast-1.compute.amazonaws.com`).
- Subnet 47.128.119.0/24 has an abuse density of 0.2462, indicating a small but non-negligible risk of malicious activity within the network.
2. Threat Indicators:
- No direct malicious indicators (no known campaigns, spam, or blacklists).
- Historical data shows minimal threat signals (26 pulses detected over 30 days, but no persistent malicious activity).
- No Tor exit nodes, VPNs, or CDN associations.
3. Neighbor Analysis:
- The subnet contains 85 IPs, with 68 medium-risk and 16 low-risk siblings.
- Notable neighbors include IPs with risk scores up to 40, suggesting potential for lateral movement or shared infrastructure risks.
4. Operational Context:
- AWS infrastructure is inherently secure, but misconfigurations or compromised instances could elevate risk.
- DNSSEC and CAA records are valid, but the subnetβs mixed risk profile warrants closer monitoring.
Recommendations:
- Monitor Subnet Activity: Track traffic patterns in 47.128.119.0/24 for anomalies, particularly given the presence of medium-risk neighbors.
- Verify AWS Security: Ensure the EC2 instance is configured with proper security groups, IAM roles, and access controls.
- Investigate Neighbors: Prioritize investigation of high-risk IPs in the subnet to identify potential shared vulnerabilities or malicious actors.
- Maintain Baseline: Use historical data to establish a baseline for this IPβs behavior, as no persistent threats were detected.
Conclusion:
While the IP itself is legitimate AWS infrastructure, its subnetβs mixed risk profile necessitates vigilance. SOC teams should focus on subnet-level monitoring and ensure AWS security best practices are enforced to mitigate potential risks from neighboring IPs.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-119-181.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-119-181.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-17 21:15:45 UTC |
| Last Seen | 2026-06-28 05:54:01 UTC |
| Profile Built | 2026-06-28 23:58:00 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.