INTELLIGENCE BRIEFING: 47.128.121.152
Classification: MODERATE RISK β Cloud Infrastructure
Date Generated: 2026-06-18
Primary Risk Indicator: Subnet-level abuse density (0.6104)
---
IP Overview
- Address: 47.128.121.152/32
- Risk Score: 40/100 (Moderate Risk)
- Provider: Amazon Web Services (AS16509)
- Organization: Amazon Data Services Singapore
- Geolocation: Singapore (1.35°N, 103.82°E)
- Infrastructure Type: CloudCompute / EC2 Instance
- PTR Record: ec2-47-128-121-152.ap-southeast-1.compute.amazonaws.com
Network Classification
- Role: Cloud hosting infrastructure
- Services: No open ports detected (firewalled/no services exposed)
- DNS: Forward confirmed; SPF and DMARC records present
- Control Plane: Route stability flagged as false; DNSSEC valid; 1 DNSBL listing observed
Threat Analysis
- Threat Indicators: No direct threat indicators (not Tor exit, not known attacker, not spam source)
- Blacklist Status: 0 direct blacklists in main profile; 1 DNSBL listing in control plane data
- Campaign Association: No correlated campaigns or threat feeds matched
- Persistence: Threat observation count: 1; not persistently malicious
Neighborhood Context (47.128.121.0/24)
- Abuse Density: 0.6104 (high abuse classification)
- Total Siblings: 78 IPs
- Active Siblings: 54
- Threat Siblings: 47
- Inherited Risk: 24
- Observation: Subnet shows elevated abuse density with significant portion of neighbors flagged as threats
Historical Trend
- Observations: 23 historical observations recorded
- Recent Activity:
- 2026-06-18: Subnet classified as "high_abuse" with 0.6104 abuse density
- 2026-06-14: DNSBL listings observed with maximum severity "high"
- Trend: Persistent monitoring shows subnet-level risk rather than IP-specific threat escalation
Recommended Actions
- Monitoring: Continue monitoring due to high-abuse subnet context
- Ingress Filtering: Apply standard cloud infrastructure filtering rules
- Egress Analysis: Investigate any outbound connections from this instance
- Correlation: Cross-reference with 47 other threat-siblings in subnet for coordinated activity analysis
Intelligence Assessment
IP 47.128.121.152 is an Amazon EC2 instance in Singapore with moderate individual risk (40/100) but elevated contextual risk due to subnet abuse density. The IP is properly registered with AWS, maintains DNSSEC, and shows no direct threat indicators. Risk is primarily inherited from the 47.128.121.0/24 subnet showing high abuse classification. No immediate threat action required; continue baseline monitoring and correlate with neighboring threat IPs for potential coordinated activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-121-152.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-121-152.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:23 UTC |
| Last Seen | 2026-06-27 05:50:03 UTC |
| Profile Built | 2026-06-27 23:55:41 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.