# Threat Intelligence Briefing: 47.128.120.214/32
Classification: Low Risk Cloud Infrastructure
Date: 2026-06-28
Analyst: IPDebrief Intelligence Team
## Executive Summary
IP address 47.128.120.214 is identified as an Amazon Web Services (AWS) EC2 instance deployed in the Singapore region (ap-southeast-1). Risk assessment indicates low threat posture with a score of 25/100. No active threat indicators, blacklisting, or malicious campaign associations detected.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 47.128.120.214/32 |
| **ASN** | 16509 |
| **Organization** | Amazon Data Services Singapore |
| **Location** | Singapore (1.35°N, 103.82°E) |
| **Network Role** | Cloud Provider (AWS) |
| **DNS Resolution** | ec2-47-128-120-214.ap-southeast-1.compute.amazonaws.com |
| **Risk Score** | 25 (Low Risk) |
## Threat Assessment
Threat Indicators: None
- Blacklist count: 0
- Known attacker: No
- Spam source: No
- Tor exit node: No
- Malicious campaigns: None
Services: No open ports detected. Instance is firewalled with no publicly accessible services.
## Network Context
Subnet Analysis (47.128.120.0/24):
- Total siblings: 14
- Abuse density: 0.5 (moderate)
- Classification: Mixed
- Inherited risk: 17
BGP Routing: Stable route with prefix 47.128.0.0/14. Route stability confirmed over 9,531 days. Operator score: 0.5217 (Moderate).
## Historical Observations
26 signal observations recorded across the monitoring period. Recent activity includes:
- Routing and geolocation signals observed on 2026-06-28
- No persistent malicious activity (threat persistence: 0 days)
- Single threat observation recorded, no sustained campaign detected
## Relationship Graph
32 relationships identified:
- DNS associations to AWS EC2 hostname
- Network association to AMAZON-SIN
- No associations to malicious entities or known bad actors
## Recommended Actions
Current Risk Level: Low - No immediate action required.
Standard Monitoring: Continue routine cloud provider infrastructure monitoring. Apply standard AWS security baselines.
Firewall Rules: No specific blocking recommended. Standard cloud provider allow-listing applies.
Notes: This IP represents legitimate AWS cloud infrastructure. The moderate abuse density (0.5) in the /24 subnet reflects typical mixed-use characteristics of AWS EC2 ranges. No defensive action required beyond standard operational monitoring.
---
*Intelligence generated from IPDebrief analysis. Data sourced from passive observations, BGP routing tables, and threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-120-214.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-120-214.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 24% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 27% | 3 | 4 |
| reputation | 30% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 23% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-16 21:01:12 UTC |
| Last Seen | 2026-06-28 04:00:51 UTC |
| Profile Built | 2026-06-29 04:06:30 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 29 |
Full dossier details are available via our API.