# IP Intelligence Briefing: 121.133.130.12
## Executive Summary
The IP address 121.133.130.12 presents a moderate risk profile (55/100) with characteristics consistent with a mobile-originated web service endpoint. The IP is associated with KT Corporation's mobile network infrastructure in Seoul, South Korea, and operates behind a residential/mobile provider classification.
## Ownership and Infrastructure
Network Assignment:
- ASN: 4766 (KORNET-KR)
- Organization: IP Manager
- CIDR Block: 121.128.0.0/11
- RIR: APNIC
Geolocation:
- Country: South Korea (KR)
- Region: Seoul, Songpa-gu
- Coordinates: 35.91°N, 127.77°E
- Accuracy: 250 km radius
Mobile Carrier:
- Carrier: KT Corporation
- Technology: LTE/5G
- Connection: Mobile network origin confirmed
## Technical Profile
Service Enumeration:
- Port 80/TCP: HTTP (nginx server)
- Port 443/TCP: HTTPS (nginx server)
- Port 22/TCP: SSH (OpenSSH_8.2)
TLS Certificate:
- Issuer: Let's Encrypt
- Subject: CN=wocjf84.synology.me
- SANs: *.wocjf84.synology.me, wocjf84.synology.me
- Certificate Type: Third-party (non-self-signed)
DNS Configuration:
- PTR Hostnames: None
- Forward Resolution: Unconfirmed
- Hosted Domains: 0
- Email Authentication: No SPF/DMARC records
- DNSBL Status: Listed on 3 of 8 DNSBL feeds
Control Plane:
- BGP Prefix: 121.128.0.0/13
- Route Stability: Unstable
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
## Threat Assessment
Risk Indicators:
- Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence: None documented
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None identified
Threat Feeds:
- Pulsedive Risk: Not available
- Threat Feeds: Empty
- Reputation Sources: None
## Behavioral History
Observation Timeline:
- Total Signals: 16 observations
- Latest Activity: July 29, 2026
- Ownership Changes: 0
- Threat Persistence: 0 days
- Persistently Malicious: False
Signal Confidence:
- Geolocation Confidence: 0.52 (Medium)
- Ownership Confidence: 0.85 (High)
- Neighbor Classification Confidence: 0.40 (Low-Medium)
- HTTP Fingerprint Confidence: 0.80 (High)
HTTP Response Analysis:
- Status Code: 200
- Server: nginx
- Response Time: 675ms
- HSTS: Not enabled
- CORS: * (allow all)
## Network Neighborhood
Subnet Analysis (121.133.130.12/24):
- Abuse Density: 0
- Classification: Clean
- Threat Siblings: 0
- Active Siblings: 1
- Inherited Risk: 0
## Associated Entities
Relationships:
- Same Network: KORNET-KR (3 instances)
- Related Networks: No external relationships detected
Campaign Correlation:
- Cert Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
- Cert Subjects: None identified
## Recommended Security Actions
Immediate Actions Required:
1. Monitor Activity: Increase logging verbosity and review recent activity from this IP due to elevated risk score (55/100)
Firewall Rule Recommendations:
- iptables: `iptables -A INPUT -s 121.133.130.12 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 121.133.130.12 drop`
- nginx: `deny 121.133.130.12;`
- pfSense: `121.133.130.12/32`
- Cloudflare WAF: Block IP (expression: `ip.src eq 121.133.130.12`)
- AWS WAF: Add to protected addresses list
Analysis Notes:
The IP exhibits characteristics of a legitimate web server operating on mobile infrastructure, but the elevated risk score (55/100) combined with DNSBL listings warrants defensive measures. The mobile carrier classification and residential/mobile infrastructure type suggest potential for abuse vectors commonly associated with mobile proxy services or compromised IoT devices.
The Let's Encrypt certificate for "wocjf84.synology.me" indicates a Synology NAS or similar device, which may be misconfigured or repurposed for unauthorized services. The absence of email authentication (SPF/DMARC) increases the likelihood of email spoofing if the IP is compromised.
Priority: Medium - Monitor and evaluate against traffic baseline before implementing blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IP Manager |
| ASN | AS4766 |
| Network Name | KORNET-KR |
| CIDR Block | 121.128.0.0/11 |
| RIR | APNIC |
| Country | KR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.2 |
๐ TLS Certificate
| SANs | *.wocjf84.synology.mewocjf84.synology.me |
| Valid From | 2026-06-26T20:37:50+00:00 |
| Valid Until | 2026-09-24T20:37:49+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 056A5401EC2BCBB725743DBD03CCA2261A0E |
| Thumbprint | 5F023BE36147AE2F307BAFA786377F57AFE32C8B |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:54:37 UTC |
| Last Seen | 2026-07-29 08:22:41 UTC |
| Profile Built | 2026-07-29 08:34:32 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.