IPDebrief

121.133.130.12

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 121.133.130.12

## Executive Summary

The IP address 121.133.130.12 presents a moderate risk profile (55/100) with characteristics consistent with a mobile-originated web service endpoint. The IP is associated with KT Corporation's mobile network infrastructure in Seoul, South Korea, and operates behind a residential/mobile provider classification.

## Ownership and Infrastructure

Network Assignment:

Geolocation:

Mobile Carrier:

## Technical Profile

Service Enumeration:

TLS Certificate:

DNS Configuration:

Control Plane:

## Threat Assessment

Risk Indicators:

Threat Feeds:

## Behavioral History

Observation Timeline:

Signal Confidence:

HTTP Response Analysis:

## Network Neighborhood

Subnet Analysis (121.133.130.12/24):

## Associated Entities

Relationships:

Campaign Correlation:

## Recommended Security Actions

Immediate Actions Required:

1. Monitor Activity: Increase logging verbosity and review recent activity from this IP due to elevated risk score (55/100)

Firewall Rule Recommendations:

Analysis Notes:

The IP exhibits characteristics of a legitimate web server operating on mobile infrastructure, but the elevated risk score (55/100) combined with DNSBL listings warrants defensive measures. The mobile carrier classification and residential/mobile infrastructure type suggest potential for abuse vectors commonly associated with mobile proxy services or compromised IoT devices.

The Let's Encrypt certificate for "wocjf84.synology.me" indicates a Synology NAS or similar device, which may be misconfigured or repurposed for unauthorized services. The absence of email authentication (SPF/DMARC) increases the likelihood of email spoofing if the IP is compromised.

Priority: Medium - Monitor and evaluate against traffic baseline before implementing blocking.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฐ๐Ÿ‡ท South Korea
RegionSeoul
CitySongpa-gu
TimezoneAsia/Seoul
Latitude35.91
Longitude127.77

๐Ÿข Ownership & Registration

OrganizationIP Manager
ASNAS4766
Network NameKORNET-KR
CIDR Block121.128.0.0/11
RIRAPNIC
CountryKR
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.2

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=wocjf84.synology.me
Issued by CN=YE1, O=Let's Encrypt, C=US
Self-signed: No
SANs*.wocjf84.synology.mewocjf84.synology.me
Valid From2026-06-26T20:37:50+00:00
Valid Until2026-09-24T20:37:49+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number056A5401EC2BCBB725743DBD03CCA2261A0E
Thumbprint5F023BE36147AE2F307BAFA786377F57AFE32C8B

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
0%
00
Overall16%45
Coverage: 4/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-21 12:54:37 UTC
Last Seen2026-07-29 08:22:41 UTC
Profile Built2026-07-29 08:34:32 UTC
Data FreshnessLive
Signal Types17
Total Observations17
๐Ÿ” 17 signal types ยท 17 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.