## IP Intelligence Briefing: 47.128.121.182/32
Classification: Moderate Risk | Jurisdiction: Singapore | Provider: Amazon Web Services
---
Executive Summary
IP address 47.128.121.182 is an Amazon Web Services EC2 instance deployed in the Singapore region (ap-southeast-1) under organization AMAZON-SIN (ASN 16509). The IP presents a moderate risk profile (Risk Score: 40) with no active threat indicators, though it resides within a subnet exhibiting elevated abuse density. No open services or ports are exposed.
Infrastructure Profile
- ASN: 16509 (Amazon Data Services Singapore)
- Organization: AMAZON-SIN / Amazon Web Services
- Location: Singapore, SG (1.35°N, 103.82°E)
- Infrastructure Type: CloudCompute
- Network Role: Provider / Hosting
- DNS Resolution: ec2-47-128-121-182.ap-southeast-1.compute.amazonaws.com
Threat Assessment
- Risk Score: 40 (Moderate)
- Known Threat Indicators: None
- Blacklist Status: Clean (0 blacklists)
- Abuse Confidence Score: Not applicable
- Campaign Correlation: None detected
- Known Attacker Status: Not listed
Network Context
The IP resides within subnet 47.128.121.0/24, which demonstrates elevated abuse characteristics:
- Subnet Abuse Density: 0.6375 (High Abuse Classification)
- Total Subnet Siblings: 80
- Active Siblings: 56
- Threat Siblings: 51
Risk distribution across the subnet shows 79 medium-risk and 9 low-risk neighbors, with no high-risk classifications. This indicates the subnet hosts legitimate cloud infrastructure alongside abuse activities common in high-density cloud environments.
Service Analysis
- Open Ports: None detected
- HTTP/HTTPS Services: None exposed
- TLS Certificates: None
- Network Status: Firewalled / No Services
- DNS Forward Resolution: Confirmed
Temporal Analysis
- Total Observations: 22 signals recorded
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: False
- Recent Signals Include:
- Cloud provider classification (confidence: 0.90)
- Subnet abuse classification as high_abuse (confidence: 0.75)
- Geolocation inference for Singapore (confidence: 0.56)
Control Plane & Routing
- BGP Prefix: 47.128.0.0/14
- Route Stability: False
- DNSBL Listings: 1 of 8 total lists
- RPKI State: Not verified
- Operator Score: 0.2609 (Basic)
Recommended Actions
Given the moderate risk score and subnet context, consider the following firewall rules:
iptables:
```
iptables -A INPUT -s 47.128.121.182 -j DROP
```
AWS WAF Configuration:
```json
{
"Addresses": ["47.128.121.182/32"],
"Description": "IPDebrief risk 40"
}
```
Note: Recommendations are probabilistic and should be combined with other contextual signals before implementation. The IP shows no open services and no active threat indicators, suggesting the risk may be inherited from subnet-level activity rather than IP-specific malicious behavior.
Intelligence Conclusion
This IP represents a legitimate AWS cloud infrastructure asset with no evidence of direct malicious activity. The moderate risk classification stems primarily from subnet-level abuse density rather than IP-specific threat indicators. No immediate blocking is required unless additional context indicates the IP is being targeted or used in specific attack campaigns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | AMAZON-SIN |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-121-182.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-121-182.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 23:04:46 UTC |
| Last Seen | 2026-06-29 08:09:54 UTC |
| Profile Built | 2026-06-29 08:14:17 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.