# IP Intelligence Briefing: 121.189.88.109
## Executive Summary
IP 121.189.88.109 is classified as High Risk with an overall risk score of 80. The address is a mobile IP address assigned to KT Corporation's LTE/5G network in Jeju City, South Korea. No open services are detected, but the IP is listed on 5 of 8 DNS blacklists and shows historical threat activity.
## Technical Profile
- IP Address: 121.189.88.109/32
- ASN: 4766 (KIXS-AS-KR - Korea Telecom)
- Organization: IP Manager
- Geolocation: Jeju City, South Korea (35.91°N, 127.77°E)
- Network Type: Mobile (KT Corporation)
- Connection Technology: LTE/5G (MCC: 450, MNC: 08)
- Risk Score: 80/100 (High Risk)
## Threat Indicators
- DNSBL Listed: 5/8 blacklists
- Threat Reputation: Historical observations indicate threat activity (35 threat pulses detected on 2026-06-17)
- Mobile Classification: Confirmed mobile IP with no residential classification
- Services: No open ports detected; service banner indicates "Firewalled / No Services"
- Tor/Proxy: Not a Tor exit node; no proxy detection
## Network Context
- Subnet: 121.189.88.0/24
- Subnet Classification: Clean (abuse density: 0)
- Neighbor Count: 0 active neighbors
- Network Relationships: Multiple relationships identified with KORNET-KR (Korea Telecom network)
- BGP Prefix: 121.176.0.0/12 (origin ASN 4766)
- Route Stability: Flagged as not stable (route changes observed)
## Observation History
Analysis of 15 historical observations reveals:
- Consistent ASN: ASN 4766 (Korea Telecom) observed across all records
- Geolocation Consistency: Jeju City, KR consistently reported
- Threat Persistence: Single observation (2026-06-17) flagged with `has_threats: true` and 35 threat pulses
- Operator Score: Minimal (0.1304)
## Recommended Actions
Based on the risk profile, the following actions are recommended:
1. Firewall Rules: Block or rate-limit traffic from this mobile IP address
2. Monitoring: Enable enhanced monitoring for any traffic from this subnet
3. Threat Intel Integration: Add to threat feed for mobile IP abuse patterns
4. Investigation: Correlate with known mobile IP abuse campaigns in the KR region
## Assessment
This mobile IP address exhibits characteristics consistent with mobile carrier abuse patterns. While no active services are detected, the high risk score, DNSBL listings, and historical threat indicators warrant defensive measures. The clean subnet classification suggests this risk is IP-specific rather than network-wide.
---
*Report generated via IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IP Manager |
| ASN | AS4766 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 21% | 1 | 2 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 21% | 2 | 2 |
| Overall | 19% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:35 UTC |
| Last Seen | 2026-06-26 18:10:32 UTC |
| Profile Built | 2026-06-22 11:56:48 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 19 |
Full dossier details are available via our API.