# IP Intelligence Briefing: 185.80.91.81/32
Classification: LOW RISK
Date: 2026-06-17
Source: IPDebrief Intelligence Platform
---
## Executive Summary
IP 185.80.91.81 presents a low-risk profile with a risk score of 25. The address operates as a web server from Russia under RIPE registry allocation (ASN 216334). While the IP maintains a stable operational posture with no persistent malicious activity detected, it exhibits one DNSBL listing and shows recent connection failure signals. No immediate blocking action is required, but monitoring is recommended.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25 |
| **Country** | Russia (RU) |
| **ASN** | 216334 |
| **Organization** | Network department |
| **RIR** | RIPE |
| **BGP Prefix** | 185.80.91.0/24 |
| **AS Path** | 6939 โ 216334 |
| **DNSBL Listed** | 1 of 8 |
| **Route Stability** | Stable (0 route changes in 30 days) |
---
## Network Services & Infrastructure
The IP operates three services:
- Port 80/tcp (HTTP) โ Standard web traffic
- Port 443/tcp (HTTPS) โ Encrypted web traffic
- Port 22/tcp (SSH) โ OpenSSH 9.6p1 Ubuntu-3ubuntu13.16
Web Server Fingerprint: Caddy web server detected. No TLS certificate currently associated with the IP.
DNS Resolution: PTR record resolves to 215075.landvps.online. Forward DNS confirmation unavailable. No SPF or DMARC records present.
---
## Threat Assessment
Threat Indicators: None detected
- Not a known attacker
- Not a spam source
- Not a Tor exit node
- No associated threat campaigns
DNSBL Status: Listed on 1 of 8 threat feeds. Classification: Minimal operator risk (operator score: 0.1304).
Abuse Confidence: Null (insufficient data for confidence scoring).
---
## Observation History
Total signals observed: 23
Recent Activity (2026-06-17):
- Connection failures observed on HTTPS probes
- Port scanning activity detected across multiple ports
- ASN 216334 allocation confirmed (registered 2023-09-08, age: 1,013 days)
- BGP prefix 185.80.91.0/24 remains stable with zero changes in 30-day window
Temporal Analysis: No persistent malicious behavior detected. Threat persistence days: 0.
---
## Neighborhood & Relationship Context
Subnet Analysis (185.80.91.0/24):
- Abuse Density: 0
- Classification: mostly_clean
- Total Siblings: 1
- Threat Siblings: 1
- Inherited Risk: 2
Network Relationships: 42 relationships identified, primarily Same Network associations with RU-landvps network designation.
---
## Recommended Actions
No immediate firewall rules or blocking actions recommended. The IP presents below-threshold risk for most security policies. Standard monitoring practices should apply.
Firewall Recommendations: None
Monitoring Priority: Low
---
## Intelligence Conclusion
The IP address 185.80.91.81 operates as a legitimate web server infrastructure from Russia with standard web services and SSH access. Risk indicators are minimal, with the sole concern being a single DNSBL listing. The network environment shows low abuse density and stable routing characteristics. No evidence of malicious activity or persistent threat behavior. Continue routine monitoring without elevated alerting.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network department |
| ASN | AS216334 |
| Network Name | โ |
| CIDR Block | 185.80.91.0/24 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 215075.landvps.online |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 215075.landvps.online |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Caddy |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 32% | 2 | 3 |
| services | 29% | 2 | 3 |
| ownership | 29% | 3 | 4 |
| reputation | 24% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 27% | 12 | 19 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:01 UTC |
| Last Seen | 2026-06-23 01:21:05 UTC |
| Profile Built | 2026-06-23 01:27:18 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 28 |
Full dossier details are available via our API.