# IP INTELLIGENCE BRIEFING: 47.128.122.117
Classification: Moderate Risk | Date: Current | Severity: LOW-MEDIUM
---
## EXECUTIVE SUMMARY
IP address 47.128.122.117 is an AWS EC2 instance hosted in Singapore (ap-southeast-1). The IP registers a risk score of 40 (Moderate Risk) with no active threat indicators, though it is part of a subnet with elevated abuse density. No malicious activity has been observed, but defensive blocking is recommended due to neighborhood context.
---
## OWNERSHIP AND GEOLOCATION
- Organization: Amazon Data Services Singapore
- ASN: 16509 (AMAZON-AS)
- CIDR Block: 47.128.0.0/14
- Geolocation: Singapore (1.35°N, 103.82°E)
- Infrastructure Type: Cloud Hosting (AWS EC2)
- PTR Hostname: ec2-47-128-122-117.ap-southeast-1.compute.amazonaws.com
---
## RISK ASSESSMENT
| Metric | Value |
|---|---|
| **Risk Score** | 40/100 (Moderate) |
| **Abuse Confidence** | Not flagged |
| **Blacklist Count** | 0 |
| **Tor Exit Node** | No |
| **Known Attacker** | No |
| **Spam Source** | No |
| **DNSBL Listed** | 1 of 8 lists |
Threat Indicators: None detected. No active campaigns, known malware, or scanning behavior observed.
---
## NETWORK CONTEXT
Subnet Analysis (47.128.122.0/24):
- Classification: High Abuse Density
- Abuse Density Score: 0.6053 (elevated)
- Total Siblings: 38
- Active Siblings: 25
- Threat Siblings: 23
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 23
- Low Risk: 14
The subnet shows a pattern of compromised or misconfigured instances typical of cloud abuse scenarios. The target IP (47.128.122.117) carries an inherited risk score of 24 from neighborhood context.
---
## OBSERVATION HISTORY
Signal observations from June 2026 confirm:
- Ownership Stability: No ownership changes detected
- Threat Persistence: 0 days of persistent malicious activity
- Subnet Abuse: Confirmed high-abuse classification (0.6053 density)
- Control Plane: Route changes recorded, RPKI validation pending
No escalation in risk posture over the observation window.
---
## SERVICE ANALYSIS
- Open Ports: None detected
- HTTP Services: None
- TLS Certificates: None
- Server Banner: None
- Connection Type: Firewalled/No Services
The instance appears dormant or heavily restricted, consistent with legitimate cloud infrastructure.
---
## RELATIONSHIP GRAPH
- DNS Associations: ec2-47-128-122-117.ap-southeast-1.compute.amazonaws.com
- Network Affiliation: AMAZON-SIN
- Organizational Links: None detected
- Certificate Subjects: None
---
## RECOMMENDED ACTIONS
Firewall Rules (Apply with caution)
```
# iptables
iptables -A INPUT -s 47.128.122.117 -j DROP
# nftables
nft add rule inet filter input ip saddr 47.128.122.117 drop
# pfSense
47.128.122.117/32
```
WAF Rules
```json
// Cloudflare WAF
{"description": "Block 47.128.122.117 β IPDebrief risk score 40", "action": "block", "filter": {"expression": "ip.src eq 47.128.122.117"}}
// AWS WAF
{"Addresses": ["47.128.122.117/32"], "Description": "IPDebrief risk 40"}
```
---
## ANALYST NOTES
This IP represents legitimate AWS infrastructure but operates within a high-abuse subnet. While the IP itself shows no malicious indicators, the elevated neighborhood risk (0.6053 abuse density) warrants defensive positioning. If traffic from this IP is observed, apply blocking rules and monitor for pattern escalation. Consider implementing rate limiting rather than hard blocking if business operations require AWS connectivity from this CIDR block.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Amazon Data Services Singapore |
| ASN | AS16509 |
| Network Name | AMAZON-SIN |
| CIDR Block | 47.128.0.0/14 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ec2-47-128-122-117.ap-southeast-1.compute.amazonaws.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ec2-47-128-122-117.ap-southeast-1.compute.amazonaws.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 24% | 2 | 2 |
| Overall | 22% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-08 14:09:18 UTC |
| Last Seen | 2026-06-21 15:11:12 UTC |
| Profile Built | 2026-06-21 15:22:57 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.