# IP Intelligence Briefing: 80.120.78.158
## Executive Summary
IP address 80.120.78.158 presents a moderate risk profile (Risk Score: 40) with minimal operational indicators. The address is assigned to AS8447 (ZANGERLEOTTO-HWY-AT) within Austria's RIPE registry. Current observations indicate limited threat activity with a clean subnet classification and zero abuse density in the immediate neighborhood.
---
## Asset Profile
| Attribute | Value |
|---|---|
| **IP Address** | 80.120.78.158/32 |
| **Organization** | AS8447-MNT (ZANGERLEOTTO-HWY-AT) |
| **ASN** | 8447 |
| **Country** | Austria (AT) |
| **City/Region** | Innsbruck, Tyrol |
| **CIDR Block** | 80.120.78.156/30 |
| **RIR** | RIPE |
| **Registration Date** | Not available |
| **Service Classification** | Web Server |
---
## Technical Observations
Network Services
- Open Ports: TCP/443 (HTTPS)
- TLS Certificate: None detected
- HTTP Title: None detected
- Server Banner: No server identification
- DNS Records: No PTR hostnames; forward resolution failed
Control Plane Intelligence
- Operator Score: 0.1304 (Minimal)
- DNSSEC Validation: Valid
- DNSBL Listings: 2 of 8 total lists
- Route Stability: Unstable
- BGP Prefix: 80.120.0.0/14
- Origin ASN: 8447
Geolocation
- Coordinates: 47.52°N, 14.55°E
- Accuracy: ±200km
- Consensus: Confirmed across multiple sources
- Plausibility: Flagged as implausible in validation
---
## Threat Intelligence Indicators
Risk Assessment
- Overall Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not available
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Persistent Malicious Activity: No
Blacklist Status
- DNSBL Listed: 2 of 8 total lists
- Threat Feeds: None detected
- Known Campaigns: None
Behavioral Signals
- Honeypot Hits: 0
- Enumeration Strikes: None detected
- Threat Persistence: 0 days
- Threat Observation Count: 0
---
## Historical Analysis
Observation Count: 17 signals recorded
Recent Activity (2026-07-30):
- 00:30:01 UTC โ Subnet classified as "clean" with zero inherited risk
- 00:29:33 UTC โ HTTPS connection attempts observed
- 00:28:01 UTC โ Geographic location inferred to Austria (confidence: 0.52)
- 00:28:01 UTC โ Port scanning activity detected
- 00:25:37 UTC โ Operator score rated as "Minimal" (0.1304)
Temporal Analysis: No persistent malicious behavior detected. The IP demonstrates minimal threat persistence and no correlation with known campaigns.
---
## Network Relationships
Connected Entities
- Network: ZANGERLEOTTO-HWY-AT (Multiple relationships detected)
Subnet Analysis (80.120.78.0/24)
- Neighbor Count: 0
- Abuse Density: 0%
- Risk Distribution: 0 high / 0 medium / 0 low threat IPs
- Classification: Clean
- Active Siblings: 1
---
## Network Path Analysis
Traceroute Summary:
- Hop Count: 15
- First Hop RTT: 0.2ms
- Last Hop RTT: 137.1ms
- Timed Out Hops: 1
- Transit Networks: Comcast detected
---
## Recommended Actions
Monitoring Priority
LOW โ The IP presents moderate risk with minimal actionable threat indicators.
Firewall Recommendations
No specific blocking actions recommended based on current threat profile. Standard HTTPS traffic should be permitted.
SOC Alerting
- Current Status: Monitor for escalation
- Recommended Thresholds: None โ below standard alert criteria
- Correlation: No active campaigns detected
---
## Intelligence Assessment
The IP address 80.120.78.158 demonstrates a moderate risk profile primarily driven by DNSBL listings (2 of 8 lists) rather than active malicious behavior. The subnet shows no abuse density, and the operator score remains minimal. Despite the moderate risk score, the IP lacks indicators of persistent malicious activity, known campaign participation, or known attacker status.
Recommendation: Maintain standard monitoring without aggressive blocking. The IP appears to be a legitimate web server endpoint with minimal threat posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | AS8447-MNT |
| ASN | AS8447 |
| Network Name | ZANGERLEOTTO-HWY-AT |
| CIDR Block | 80.120.78.156/30 |
| RIR | RIPE |
| Country | AT |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 50% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 14:26:53 UTC |
| Last Seen | 2026-07-30 00:24:15 UTC |
| Profile Built | 2026-07-30 00:32:57 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.