# IP INTELLIGENCE BRIEFING
Subject: 217.26.179.25/32
Classification: High Risk (80/100)
Report Generated: 2026-06-26
---
## EXECUTIVE SUMMARY
IP address 217.26.179.25 is a single-service host located in Oristano, Italy, operating under ASN 209353 (Fanari Maurizio). The IP exhibits elevated risk characteristics with a risk score of 80/100 and is listed on 4 of 8 DNSBLs. The /24 neighborhood shows mixed classification with 30 threat siblings out of 72 total neighbors (41.7% threat density). Defensive action is recommended.
---
## OWNERSHIP & GEOLLOCATION
- Organization: Fanari Maurizio (trading as LABEL SISTEMI TECNOLOGICI, IT)
- ASN: 209353
- Registration: RIPE (2018-09-28)
- Geolocation: Oristano, Italy (IT)
- CIDR Block: 217.26.176.0/22
- Network Type: Single-Service Host
---
## NETWORK SERVICES
- Open Ports: TCP/80 (HTTP)
- Server Banner: lighttpd/1.4.39
- HTTP Status: 302 (Redirect)
- HTTP Version: 1.1
- TLS Certificate: None
- DNS: No PTR records, no forward resolution confirmed
---
## THREAT ASSESSMENT
| Indicator | Status |
|---|---|
| **Risk Score** | 80/100 (High) |
| **DNSBL Listings** | 4 of 8 lists |
| **Tor Exit Node** | No |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Abuse Confidence** | Elevated |
Historical Context: 16 observations recorded between 2026-06-05 and 2026-06-26. Consistent lighttpd fingerprint and ASN ownership observed throughout the observation period. No persistent malicious activity flagged.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 217.26.179.0/24
- Total Neighbors: 79 IPs
- Active Siblings: 28
- Threat Siblings: 30
- Abuse Density: 0.139 (13.9%)
- Risk Distribution: 11 high-risk, 59 medium-risk, 9 low-risk
Notable High-Risk Neighbors:
- 217.26.179.19 (Risk: 80)
- 217.26.179.5 (Risk: 55)
- 217.26.179.13 (Risk: 55)
- 217.26.179.14 (Risk: 55)
- 217.26.179.21 (Risk: 55)
---
## RECOMMENDED ACTIONS
Firewall Rules
iptables:
```bash
iptables -A INPUT -s 217.26.179.25 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 217.26.179.25 drop
```
nginx:
```nginx
deny 217.26.179.25;
```
WAF Integration
Cloudflare WAF: Block IP (expression: `ip.src eq 217.26.179.25`)
AWS WAF: Add to blocked IP set (CIDR: `217.26.179.25/32`)
General Recommendation: Increase logging verbosity and review recent activity from this IP source due to elevated risk score (80/100).
---
## INTELLIGENCE NOTES
1. The IP's 302 redirect behavior may indicate proxy usage or content redirection
2. Lighttpd 1.4.39 is a relatively older web server; verify if this is a legitimate hosting service or repurposed infrastructure
3. Neighborhood risk suggests this subnet may be used for bulk hosting services
4. Four DNSBL listings correlate with the overall high-risk classification
5. No evidence of active malicious campaigns or known threat associations
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Fanari Maurizio |
| ASN | AS209353 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 10:13:43 UTC |
| Last Seen | 2026-06-26 18:11:08 UTC |
| Profile Built | 2026-06-26 01:01:19 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.