# IP Intelligence Briefing: 47.128.121.80/32
## Executive Summary
IP address 47.128.121.80 is a cloud-hosted Amazon Web Services EC2 instance located in Singapore (ap-southeast-1). The IP carries a moderate risk score of 40 and is associated with an abuse-dense subnet (47.128.121.0/24) showing 56.98% abuse density and 49 threat-identified siblings. No active services were detected, and the instance is firewalled with no open ports.
## Profile Details
| Attribute | Value |
|---|---|
| **ASN** | 16509 (Amazon Data Services Singapore) |
| **Organization** | Amazon Web Services |
| **Location** | Singapore, SG (1.35°N, 103.82°E) |
| **Infrastructure Type** | CloudCompute |
| **Risk Score** | 40 (Moderate Risk) |
| **Network Role** | Cloud, Hosted, Firewalled/No Services |
| **DNS Resolution** | ec2-47-128-121-80.ap-southeast-1.compute.amazonaws.com |
## Threat Indicators
- Blacklist Status: Listed on 8 DNS blacklist entries with high severity
- Threat Feeds: No indicators from known threat feeds
- Tor Exit/Proxy: Not identified as Tor exit node or proxy
- Open Ports: None detected
- TLS Certificates: None observed
- Campaign Correlation: No known campaign matches
## Neighborhood Analysis
The /24 subnet (47.128.121.0/24) exhibits elevated abuse characteristics:
- Total Siblings: 86
- Active Siblings: 64
- Threat Siblings: 49
- Risk Distribution: 0 high, 79 medium, 9 low risk
- Inherited Risk: 22
Multiple neighboring IPs show risk scores of 40, suggesting concentrated risk patterns within the subnet.
## Historical Observations
23 signal observations recorded with the following key findings:
- Most Recent: 2026-06-25
- Signal Types: TLS checks, blacklist listings, subnet analysis, geolocation validation, ASN data
- Blacklist Activity: Listed on 8 DNS blacklist entries with high severity classification
- Network Classification: High abuse designation maintained across observations
## Relationship Graph
47 relationships identified, including:
- Multiple same-network associations (AMAZON-SIN)
- DNS associations to Amazon EC2 hostname
- Provider infrastructure links
## Recommended Actions
Based on the IP's risk profile and blacklist associations, the following mitigations are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 47.128.121.80 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 47.128.121.80 drop`
- nginx: `deny 47.128.121.80;`
- pfSense: `47.128.121.80/32`
- Cloudflare WAF: Block with expression `ip.src eq 47.128.121.80`
- AWS WAF: `Addresses: ["47.128.121.80/32"]`
## Intelligence Assessment
This AWS EC2 instance presents moderate risk due to its subnet's high abuse density and blacklist presence. While no active exploitation services were detected, the IP's association with 8 high-severity blacklist listings warrants monitoring. The subnet's 49 threat siblings suggest coordinated or shared infrastructure abuse patterns. SOC teams should consider blocking at the perimeter while monitoring for any service activation or behavioral changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | β |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-121-80.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-121-80.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 49% | 2 | 5 |
| routing | 32% | 2 | 3 |
| services | 20% | 2 | 2 |
| ownership | 30% | 3 | 4 |
| reputation | 31% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 31% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 11:34:06 UTC |
| Last Seen | 2026-06-27 15:36:41 UTC |
| Profile Built | 2026-06-28 09:42:55 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 30 |
Full dossier details are available via our API.