IP Intelligence Briefing: 96.126.130.210/32
Subject: Risk Assessment and Threat Intelligence Summary
Executive Summary:
The IP address 96.126.130.210 was identified as low-risk during observation. Risk scoring returned a value of 15, with zero contributions from provider, authority, and stability metrics. The address operated under ASN 149440 (Evoxt/EVOXT) within the ARIN registry.
Network Classification:
The IP was classified as residential with no services exposed. No open ports were detected during probing. The network role was determined as firewalled with no active services. The address is not associated with cloud, CDN, VPN, proxy, Tor, hosting, mobile carrier, or bogon classifications.
Geolocation and Infrastructure:
Geolocation data placed the IP in the US region, though historical signals indicated Osaka, Japan coordinates. The address operates within the 96.126.130.0/24 CIDR block. Traceroute analysis revealed 15 hops with Comcast as a transit network; first hop RTT was 0.1ms and final hop RTT measured 183.5ms with 5 timed-out hops.
DNS and Hostname Associations:
Reverse DNS resolution returned "96-126-130-210.aceips.com". Forward resolution was not confirmed. The address has no hosted domains and zero email authentication records. SPF records were present while DMARC was absent.
Threat Indicators:
Threat feeds returned no indicators. The IP is not a Tor exit node, known attacker, or spam source. Blacklist count was 0. Abuse confidence scoring was unavailable. No known campaigns were associated with the address.
Subnet Analysis:
The 96.126.130.0/24 neighborhood contained zero sibling IPs. Abuse density was measured at 0. No high, medium, or low-risk neighbors were detected.
Temporal Behavior:
Ownership changes registered 0 instances with no threat persistence observed. Threat observation count was 0. The IP is not classified as persistently malicious.
Control Plane:
BGP prefix 96.126.130.0/24 originated from ASN 149440. The route is not stable. DNSSEC validation was confirmed as valid. CAA records were present. The IP was listed on 1 of 8 DNS blacklists.
Relationship Graph:
Five relationships were identified: two same-network associations to EVOXT, and three DNS associations to the hostname 96-126-130-210.aceips.com.
Historical Signals:
Seventeen observations were recorded. Key signals included ownership registration data from ARIN/Evoxt, geolocation indicators showing US placement with 39.83°N, 98.58°W coordinates, and network classification signals confirming the IP is not CDN, Tor, VPN, bogon, cloud, proxy, mobile, or hosting infrastructure.
Recommended Actions:
No specific firewall or security actions were recommended based on the low-risk profile.
Conclusion:
IP 96.126.130.210 presents a low-risk profile with no active threat indicators. The address is operational within Evoxt infrastructure but shows no malicious behavior. SOC teams may monitor the subnet for any changes in risk posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Evoxt |
| ASN | AS149440 |
| Network Name | EVOXT |
| CIDR Block | 96.126.130.0/24 |
| RIR | ARIN |
| Country | Japan |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 96-126-130-210.aceips.com |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 96-126-130-210.aceips.com |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 22 | ssh | tcp | Banner detected |
| 8080 | http-alt | tcp | — |
| Closed Ports | 25, 443, 3389, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS149440 |
| Network Prefix | 96.126.130.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 12% | 2 | 2 |
| Overall | 13% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-08 06:55:52 UTC |
| Last Seen | 2026-09-13 10:46:32 UTC |
| Profile Built | 2026-09-11 21:53:52 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 96.126.130.210
Who owns the IP address 96.126.130.210?
96.126.130.210 is registered to Evoxt. The address falls within the 96.126.130.0/24 network block. Registration is held at ARIN.
Where is 96.126.130.210 located?
Geolocation data places 96.126.130.210 in Osaka, Osaka, Japan. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 96.126.130.210 malicious or safe?
96.126.130.210 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 96.126.130.210?
The reverse DNS (PTR) record for 96.126.130.210 is 96-126-130-210.aceips.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 96.126.130.210?
Responsive ports observed on 96.126.130.210 include 80, 22, 8080. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.