AWS security groups block ICMP (including ping, traceroute, etc.) by default. You need to explicitly enable it.

(1) Go to EC2 Dashboard and click “Running Instances”
(2) on “Security Groups”, select the group of your instance which you need to add security.
(3) click on the “Inbound” tab
(4) Select Custom ICMP Rule – IPv4
(5) Select Echo Request
(6) Select either Anywhere or My IP
(7)Select Save