IPDebrief

47.128.122.1

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 47.128.122.1

## Executive Summary

Threat Level: MODERATE β€” Cloud compute instance hosted by Amazon Web Services Singapore (AP-South-1 region). No active threat indicators detected; however, subnet environment exhibits elevated abuse density. Monitor for anomalous behavior.

---

## Asset Profile

AttributeValue
**IP Address**47.128.122.1/32
**Organization**Amazon Data Services Singapore
**ASN**16509 (Amazon.com, Inc.)
**Geolocation**Singapore (1.35°N, 103.82°E)
**Infrastructure Type**Cloud Compute (EC2)
**Risk Score**40/100 (Moderate)
**DNSBL Listed**1 of 8 lists

---

## Technical Details

DNS Resolution:

Network Classification:

Services:

---

## Threat Indicators

Current Assessment: Clean

---

## Neighborhood Analysis

Subnet: 47.128.122.0/24

Key Finding: While 47.128.122.1 shows moderate risk, the subnet exhibits significant abuse density. Multiple adjacent IPs (47.128.122.100, 47.128.122.107, 47.128.122.116, 47.128.122.124, 47.128.122.126) maintain risk scores of 40.

---

## Historical Observations (26 signals)

Timeline: June 2026

---

## Relationship Graph

---

## Recommended Actions

Network Defense (SOC Analyst)

```

# Monitor subnet-level activity

# Block if suspicious patterns emerge in 47.128.122.0/24

iptables -A INPUT -s 47.128.122.0/24 -j LOG --log-prefix "SUBNET-MONITOR: "

# No immediate blocking recommended for 47.128.122.1

# Cloud infrastructure; whitelist unless abuse confirmed

```

SOC Guidance

1. Monitor subnet 47.128.122.0/24 for lateral movement or coordinated abuse

2. Investigate if 47.128.122.1 shows outbound traffic to known malicious destinations

3. Correlate with other AWS EC2 instances in same subnet for threat intelligence

4. No immediate takedown recommended; legitimate cloud hosting infrastructure

---

Classification: MODERATE RISK β€” Cloud infrastructure with elevated subnet risk. Maintain monitoring; no immediate mitigation required absent observable malicious activity.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
RegionSG
CitySingapore
TimezoneAsia/Singapore
Latitude1.35
Longitude103.82

🏒 Ownership & Registration

OrganizationAmazon Data Services Singapore
ASNAS16509
Network Nameβ€”
CIDR Block47.128.0.0/14
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRec2-47-128-122-1.ap-southeast-1.compute.amazonaws.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesec2-47-128-122-1.ap-southeast-1.compute.amazonaws.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
40%
23
routing
24%
23
services
15%
22
ownership
24%
34
reputation
21%
12
geolocation
33%
23
Overall26%1217
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-11 22:24:09 UTC
Last Seen2026-06-27 20:36:39 UTC
Profile Built2026-06-28 14:42:04 UTC
Data FreshnessLive
Signal Types25
Total Observations30
πŸ” 25 signal types Β· 30 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.