IP Intelligence Briefing: 47.128.122.0
*Generated for SOC Analysts*
---
**1. Core Profile**
- Risk Score: Moderate (40/100)
- Provider: Amazon Data Services Singapore (AS16509)
- Geolocation: Singapore (1.35°N, 103.82°E)
- Network Role: AWS Cloud Compute (Firewalled / No Services)
- Threat Indicators: No direct malicious activity detected.
Key Context:
- The IP is part of AWS infrastructure, associated with an EC2 instance (`ec2-47-128-122-0.ap-southeast-1.compute.amazonaws.com`).
- Subnet 47.128.122.0/24 has a high abuse density (0.5556), with 28/37 neighbors flagged as medium-risk and 9 as low-risk.
---
**2. Observation History**
- Recent Activity:
- No persistent malicious behavior detected (threat observation count = 1).
- Subnet abuse density has remained stable over the past 30 days.
- Notable Trends:
- The IP has been observed in DNS records linked to AWS services.
- No spikes in scanning or exploitation signals.
---
**3. Network Relationships**
- Primary Associations:
- Amazon Web Services (AS16509): Same network (AMAZON-SIN) and DNS records.
- Subnet: 47.128.122.0/24, which includes 37 IPs with mixed risk profiles.
- Critical Insight:
- The subnetβs high abuse density suggests potential for lateral movement or shared infrastructure risks.
---
**4. Neighborhood Analysis**
- Subnet Summary:
- Total IPs: 37 (47.128.122.0/24).
- Risk Distribution:
- Medium Risk: 28 IPs (risk scores 25β50).
- Low Risk: 9 IPs (risk scores 0β25).
- Notable Neighbors:
- IPs like 47.128.122.1, 47.128.122.12, and 47.128.122.13 show elevated risk scores (25β50).
- Actionable Insight:
- Monitor the subnet for unusual traffic patterns, as the high abuse density may indicate compromised hosts or shared malicious infrastructure.
---
**5. Recommendations**
1. Monitor Subnet Activity:
- Investigate neighbors with medium/high risk scores for potential lateral movement or malicious activity.
2. Verify AWS Infrastructure:
- Confirm the IPβs legitimacy via AWS console (e.g., EC2 instance details).
3. Isolate Suspicious Neighbors:
- Apply network segmentation or firewall rules to isolate high-risk IPs in the subnet.
4. Check for Misconfiguration:
- Ensure AWS resources are not exposed to the public internet without proper security controls.
---
Final Assessment:
The IP itself is legitimate AWS infrastructure, but its subnet exhibits high abuse density. SOC teams should prioritize monitoring the subnet for indirect threats and ensure AWS resources are properly secured.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | AMAZON-SIN |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-122-0.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-122-0.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 25% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-25 12:42:44 UTC |
| Last Seen | 2026-06-29 01:43:17 UTC |
| Profile Built | 2026-06-29 07:45:06 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.