# IP Intelligence Briefing: 47.128.121.130
## Executive Summary
The IP address 47.128.121.130 was classified as Moderate Risk (Risk Score: 40) during analysis. The address belongs to Amazon Web Services infrastructure in Singapore and operates as a cloud compute resource. While the IP itself shows no active threat indicators, the surrounding subnet exhibits high abuse density.
## Infrastructure Profile
Ownership: Amazon Data Services Singapore (ASN 16509, Netname: AMAZON-SIN)
Location: Singapore (ap-southeast-1 region)
Infrastructure Type: Cloud Compute (AWS EC2 instance)
Network Role: Firewall-enabled cloud hosting infrastructure with no services exposed
DNS Analysis:
- PTR Resolution: ec2-47-128-121-130.ap-southeast-1.compute.amazonaws.com
- Forward Resolution: Confirmed
- Email Authentication: SPF and DMARC records present
- Hosted Domains: None
## Threat Indicators
The IP address showed no direct threat indicators during assessment:
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None identified
- DNSBL Listed: 1 of 8 total lists
## Neighborhood Context Analysis
The /24 subnet (47.128.121.0/24) demonstrated elevated abuse characteristics:
- Abuse Density: 0.5676 (High Abuse Classification)
- Total Siblings: 74 IP addresses
- Active Siblings: 45
- Threat Siblings: 42
- Inherited Risk Score: 22
The neighborhood exhibited 72 medium-risk and 7 low-risk addresses, with no high-risk classifications among neighbors. This pattern is consistent with AWS cloud infrastructure where legitimate cloud customers operate alongside potentially compromised instances.
## Historical Observation
Analysis of signal history across 23 observations revealed:
- Ownership stability maintained throughout observation period
- Cloud infrastructure classification consistent
- No ownership transfers detected
- Recent observations confirm cloud compute role
## Risk Assessment
The IP's risk profile (Score: 40) reflects the inherent risk associated with AWS cloud infrastructure rather than specific malicious activity. The absence of direct threat indicators suggests the address is part of legitimate cloud operations. However, the high-abuse neighborhood classification warrants contextual consideration for security policies.
## Recommended Actions
Based on the risk profile, the following firewall rules were generated:
iptables: `iptables -A INPUT -s 47.128.121.130 -j DROP`
nftables: `nft add rule inet filter input ip saddr 47.128.121.130 drop`
nginx: `deny 47.128.121.130;`
pfSense: Block 47.128.121.130/32
Cloudflare WAF: Block with description "IPDebrief risk score 40"
AWS WAF: Include 47.128.121.130/32 in rule set
## SOC Analyst Notes
- The IP represents legitimate AWS infrastructure (EC2 instance) in Singapore
- No evidence of direct malicious activity on this specific address
- Neighborhood abuse density suggests monitoring related subnet activity
- If traffic patterns indicate abuse, block at perimeter while maintaining logging
- Consider whitelisting if this IP represents a legitimate business relationship
- Correlate with other signals before implementing blocking rules per disclaimer
Classification: Moderate Risk - Cloud Infrastructure
Confidence Level: High (based on provider classification and DNS resolution)
Action Required: Context-dependent based on traffic analysis and business requirements
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | AMAZON-SIN |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-121-130.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-121-130.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 27% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 30% | 3 | 4 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 24% | 12 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-28 12:25:51 UTC |
| Last Seen | 2026-06-29 05:31:23 UTC |
| Profile Built | 2026-06-29 05:33:41 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 26 |
Full dossier details are available via our API.