## IP Intelligence Briefing: 129.121.126.30
Classification: Moderate Risk / No Active Threat Indicators
Date: Current Analysis
Analyst: SOC Intelligence Team
---
Executive Summary
IP address 129.121.126.30 resolves to a US-based infrastructure asset hosted by Unified Layer with a moderate risk profile (score: 50/100). The IP shows no active threat indicators, no open services, and no historical malicious activity. However, the address appears on 2 DNS blacklist lists and exhibits routing characteristics consistent with the 129.121.120.0/21 BGP prefix under ASN 31898.
---
Technical Profile
Geolocation: New York, US (US-NY region)
ASN/Network: ASN 31898, BGP Prefix 129.121.120.0/21
DNS PTR: 129-121-126-30.unifiedlayer.com
Forward Resolution: Confirmed to unifiedlayer.com domain
Service Status: Firewalled / No Open Ports Detected
Infrastructure Type: Corporate/Hosting (not CDN, VPN, proxy, or Tor)
---
Risk Assessment
Overall Risk Score: 50/100 (Moderate)
Provider Score: 0 (No provider-specific risk)
Authority Score: 0 (No authority-specific risk)
Operator Score: 0.1304 (Minimal)
Threat Indicators:
- No known attacker signatures
- Not a Tor exit node
- Not identified as spam source
- Blacklist count: 0 (but listed on 2 DNSBLs)
- No active threat campaigns correlated
Control Plane:
- Route stability: False (route changes observed)
- MoAS: False (not Multi-Origin Autonomous System)
- DNSSEC: Valid
- RPKI State: Not applicable
- IRR Consistency: Not applicable
---
Observation History (12 Signals Recorded)
Recent monitoring indicates:
- DNSSEC Operator Score: "Minimal" (0.1304) as of 2026-07-30
- DNSBL Listings: 2 out of 8 total lists flagged with high severity
- Geolocation Signals: US-based with low confidence (0.35)
- Threat Persistence: No persistent malicious behavior detected
---
Relationship Network
DNS Associations:
- 129-121-126-30.unifiedlayer.com
No additional relationships detected to subnets, organizations, or certificates at this time.
---
Neighborhood Analysis
Subnet: 129.121.126.30/24
Neighbor Count: 0
Abuse Density: 0%
Risk Distribution: No high/medium/low risk neighbors detected
---
Recommended Security Actions
Based on the moderate risk profile (score 50), the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 129.121.126.30 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 129.121.126.30 drop
```
nginx:
```
deny 129.121.126.30;
```
pfSense:
```
129.121.126.30/32
```
Cloudflare WAF:
```json
{
"description": "Block 129.121.126.30 β IPDebrief risk score 50",
"action": "block",
"filter": {"expression": "ip.src eq 129.121.126.30"}
}
```
AWS WAF:
```json
{
"Addresses": ["129.121.126.30/32"],
"Description": "IPDebrief risk 50"
}
```
---
Analyst Notes
This IP address presents a moderate risk profile primarily due to DNSBL listings and routing instability. However, no active malicious activity has been observed. The lack of open services and firewalled status reduce immediate threat potential. Security teams may consider blocking this address proactively, though it is not currently flagged as actively malicious. Correlate with internal traffic logs to determine if this IP has been observed attempting connections to your infrastructure.
---
*Report generated using IPDebrief intelligence platform. Data sourced from 12 observation signals and control plane analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Oso Grande IP Services, LLC |
| ASN | AS31898 |
| Network Name | OGTIPS1-129-121 |
| CIDR Block | 129.121.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 129-121-126-30.unifiedlayer.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 129-121-126-30.unifiedlayer.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | β |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 14:52:28 UTC |
| Last Seen | 2026-08-07 19:24:28 UTC |
| Profile Built | 2026-07-30 04:20:04 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.