IP Intelligence Briefing: 47.128.122.105
Date: 2026-06-12
---
**1. Core Profile**
- Reputation: Moderate Risk (Risk Score: 40)
- Ownership:
- ASN: 16509
- Organization: Amazon Data Services Singapore (AMAZON-SIN)
- Geolocation: Singapore (City: Singapore, Latitude: 1.35, Longitude: 103.82)
- Network Role:
- Provider: Amazon Web Services (AWS)
- Type: CloudCompute (Firewalled / No Services)
- Subnet: 47.128.0.0/14
---
**2. Threat & Abuse Indicators**
- Threat Status: No direct malicious indicators (no malware, spam, or known attacker associations).
- Subnet Risk:
- Abuse Density: 55.26% (high abuse classification)
- Neighbor Analysis:
- Total Siblings: 38 IPs in 47.128.122.0/24
- Active Threat Siblings: 21 IPs (risk scores range: 0β50)
- Notable Neighbors:
- 47.128.122.100 (Risk: 40), 47.128.122.118 (Risk: 40), 47.128.122.122 (Risk: 50)
---
**3. Historical Observations**
- Geolocation Consistency: Inferred as Singapore with 56% confidence; ICMP validation blocked.
- Network Stability:
- Route Stability: Unstable (route changes detected in 30 days).
- DNSSEC: Validated.
- Threat Trends: No persistent malicious activity detected.
---
**4. Relationships & Dependencies**
- DNS Associations:
- Linked to AWS EC2 hostname: `ec2-47-128-122-105.ap-southeast-1.compute.amazonaws.com`.
- Network Relationships:
- Same network as AMAZON-SIN (AWS infrastructure).
- Control Plane:
- BGP Prefix: 47.128.0.0/14
- RPKI State: Not reported.
- Operator Score: 0.26 (Basic risk rating).
---
**5. Actionable Insights**
- Risk Mitigation:
- Monitor subnet for unusual traffic patterns due to high abuse density.
- Validate if the AWS instance is authorized (check access logs).
- Neighbor Analysis:
- Investigate high-risk neighbors (e.g., 47.128.122.122) for potential lateral movement or spoofing.
- Network Controls:
- Consider restricting traffic to/from this subnet if it contains untrusted hosts.
- Ensure AWS security groups and firewall rules are properly configured.
---
Conclusion:
The IP is a legitimate AWS cloud instance, but its subnet exhibits elevated risk due to neighboring IPs. SOC teams should prioritize monitoring the subnet and validating the necessity of the AWS resource. No immediate action is required for the IP itself, but proactive subnet-level analysis is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | AMAZON-SIN |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-122-105.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-122-105.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-01 05:39:14 UTC |
| Last Seen | 2026-06-29 09:29:31 UTC |
| Profile Built | 2026-06-29 09:47:30 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 23 |
Full dossier details are available via our API.