# IP Intelligence Briefing: 47.128.119.20/32
Classification: Moderate Risk | Date: Current | Status: Actionable
---
## Executive Summary
IP address 47.128.119.20 is an Amazon Web Services (AWS) cloud infrastructure endpoint located in Singapore (ap-southeast-1). The IP carries a moderate risk score of 40 and is associated with AWS EC2 infrastructure. While the endpoint itself shows no active open ports or direct threat indicators, the subnet exhibits elevated abuse density, warranting defensive monitoring.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 47.128.119.20/32 |
| **ASN** | AS16509 (Amazon.com, Inc.) |
| **Organization** | Amazon Data Services Singapore |
| **Location** | Singapore, SG |
| **Infrastructure** | AWS Cloud Compute |
| **DNS** | ec2-47-128-119-20.ap-southeast-1.compute.amazonaws.com |
| **Risk Score** | 40 (Moderate) |
| **Status** | Firewalled/No Services |
---
## Threat Indicators & History
Current Risk Assessment
- Threat Indicators: None currently active
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
Historical Signal Analysis
Analysis of 21 historical observations reveals:
- June 2026: Multiple threat signals detected from AlienVault OTX sources (23 pulse matches)
- Infrastructure Signals: Consistent AWS cloud compute classification
- Subnet Abuse Density: 0.5895 (High abuse classification)
- Threat Persistence: No persistent malicious activity detected
---
## Neighborhood Analysis
Subnet: 47.128.119.20/24
- Total Siblings: 95
- Active Siblings: 70
- Threat Siblings: 56
- Abuse Density: 0.5895 (High)
- Risk Classification: High Abuse
The subnet demonstrates elevated abuse activity with 59% of active siblings flagged as threats. This contextual risk factor should be considered in network segmentation decisions.
---
## Network Relationships
- DNS Associations: ec2-47-128-119-20.ap-southeast-1.compute.amazonaws.com (primary)
- Network Affiliation: AMAZON-SIN network
- Relationship Count: 42 total relationships
- Campaign Correlation: No known campaign matches
---
## Recommended Actions
Immediate Mitigation
Based on risk assessment, the following defensive measures are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 47.128.119.20 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 47.128.119.20 drop`
- nginx: `deny 47.128.119.20;`
- pfSense: `47.128.119.20/32`
- Cloudflare WAF: Block IP with expression `ip.src eq 47.128.119.20`
- AWS WAF: Add to block list with description "IPDebrief risk 40"
Monitoring Recommendations
- Monitor subnet 47.128.119.0/24 for related activity
- Implement rate limiting for AWS EC2 ranges in Singapore region
- Review historical threat signals from June 2026 for pattern correlation
---
## Analyst Notes
This IP represents a cloud infrastructure endpoint with moderate risk characteristics. The absence of open services reduces immediate exploitability, but the subnet-level abuse density warrants continued monitoring. Recommended approach: Block at network perimeter, monitor for lateral activity within the /24 subnet, and maintain threat intelligence correlation with related AWS endpoints.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-119-20.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-119-20.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 02:16:47 UTC |
| Last Seen | 2026-06-28 13:01:35 UTC |
| Profile Built | 2026-06-29 07:06:42 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.