## INTELLIGENCE BRIEFING: 47.128.121.13
EXECUTIVE SUMMARY
IP 47.128.121.13 is an Amazon Web Services EC2 instance deployed in Singapore (ap-southeast-1). The IP registers as Moderate Risk (score: 40/100) with no active threat indicators detected. Infrastructure shows firewalled status with no open services, though the /24 subnet exhibits elevated abuse activity.
INFRASTRUCTURE PROFILE
- Organization: Amazon Data Services Singapore (Amazon Web Services)
- ASN: 16509 (AMAZON-SIN)
- Geolocation: Singapore (1.35°N, 103.82°E)
- DNS Resolution: ec2-47-128-121-13.ap-southeast-1.compute.amazonaws.com
- Infrastructure Type: CloudCompute (AWS EC2)
- Network Classification: Cloud provider hosting infrastructure
THREAT ASSESSMENT
- Risk Score: 40 (Moderate Risk)
- Threat Indicators: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: 0 blacklist listings
- Services: No open ports detected (firewalled/no services)
- Campaign Association: None identified
NEIGHBORHOOD ANALYSIS
- Subnet: 47.128.121.13/24
- Abuse Density: 0.6375 (High)
- Total Siblings: 88 IPs in /24 subnet
- Risk Distribution: 79 medium risk, 9 low risk, 0 high risk
- Notable: Multiple adjacent IPs (47.128.121.6, .7, .8, .9) show matching riskScore 40 with authorityScore 60
OBSERVATION HISTORY
- Total Observations: 23 signals recorded
- Recent Activity:
- High abuse classification confirmed (abuse_density: 0.6375)
- 8 DNS blacklist listings (1 active listing with high severity)
- Basic operator score (0.2609)
- Geolocation consistently validated as Singapore
- Route stability flagged as unstable (isRouteStable: false)
RECOMMENDATIONS
1. Allow with Monitoring: Legitimate AWS infrastructure with no active threat indicators warrants allow-listing with logging.
2. Subnet Context: Elevated neighborhood abuse density (0.6375) suggests shared infrastructure risk; monitor for lateral threats.
3. Blacklist Verification: Investigate which of the 8 blacklist listings remain active and assess their severity.
4. Traffic Baseline: Establish baseline for this EC2 instance; no services detected suggests low-interaction target.
5. Route Monitoring: Route stability issues may indicate transient infrastructure changes; monitor for reassignment.
CONCLUSION
This IP represents legitimate cloud infrastructure with moderate risk characteristics. No direct threat indicators present. SOC teams should permit traffic while maintaining logging due to elevated neighborhood abuse activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | AMAZON-SIN |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-121-13.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-121-13.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 34% | 2 | 3 |
| Overall | 25% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-31 23:34:29 UTC |
| Last Seen | 2026-06-29 09:11:44 UTC |
| Profile Built | 2026-06-29 15:14:14 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.