# IP Intelligence Briefing: 80.26.154.189
Classification: Low Risk / Legitimate Infrastructure
Reporting Date: 2026-07-30
Analysis Type: Threat Intelligence Assessment
---
## Executive Summary
IP address 80.26.154.189 is a legitimate mobile carrier endpoint operated by Telefonica de Espana's Movistar network. The IP presents no threat indicators, operates within a clean subnet, and demonstrates no malicious activity over the observation period. Security teams may treat this IP as benign infrastructure.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 0 (Low Risk) |
| **Reputation** | Low Risk |
| **ASN** | 3352 (Administradores Telefonica de Espana) |
| **Network** | TDENET (80.26.152.0/21) |
| **Geolocation** | Madrid, Spain (40.4409, -3.7033) |
| **Classification** | Mobile Carrier / Firewalled |
| **Carrier** | Movistar (Telefonica de Espana SAU) |
| **Technology** | LTE/5G (MCC: 214, MNC: 07) |
---
## Network Analysis
Infrastructure Type: Mobile Carrier endpoint
Service Status: No services detected (firewalled)
DNS Resolution: `189.red-80-26-154.staticip.rima-tde.net`
PTR Record: Forward confirmed (rma-tde.net domain)
The IP resolves to a dynamic residential/mobile IP assignment within Telefonica's network infrastructure. No open ports, banners, or service signatures detected during scanning.
---
## Threat Indicators
| Indicator Type | Status |
|---|---|
| **Blacklist Count** | 0 |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Tor Exit Node** | No |
| **Vulnerability Scans** | None detected |
| **Threat Persistence** | 0 days |
| **Abuse Confidence Score** | N/A |
No threat intelligence feeds, campaigns, or malicious activity associated with this IP.
---
## Observation History
Total Observations: 17 signals recorded
Latest Signal: 2026-07-30 17:08 UTC
Recent activity indicates normal carrier operations:
- Network Scans: Routine port scanning detected with no open services
- Geolocation Signals: Consistent Madrid, Spain coordinates
- Ownership Stability: No ownership changes detected
- Operator Score: 0.2609 (Basic classification)
- Threat Persistence: None observed
The IP has maintained consistent behavior with no escalation in risk profile.
---
## Relationship Graph
| Relationship Type | Target | Count |
|---|---|---|
| Same Network | TDENET | 2 |
| DNS Association | 189.red-80-26-154.staticip.rima-tde.net | 2 |
No external entity associations, certificates, or correlated IP addresses detected.
---
## Neighborhood Analysis
Subnet: 80.26.154.189/24
Abuse Density: 0 (Clean)
Classification: Clean
Total Siblings: 1
Active Threats: 0
The /24 subnet demonstrates no abuse activity or suspicious neighbor activity.
---
## Recommended Security Actions
No action required. This IP represents legitimate carrier infrastructure with no threat indicators. Standard monitoring protocols apply.
---
## Conclusion
80.26.154.189 is a clean mobile carrier IP from Spain's Movistar network. The endpoint shows no malicious characteristics, operates within normal carrier parameters, and exists in a clean subnet. No firewall rules or blocking actions recommended. SOC teams may classify this as trusted infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Administradores Telefonica de Espana |
| ASN | AS3352 |
| Network Name | TDENET |
| CIDR Block | 80.26.152.0/21 |
| RIR | RIPE |
| Country | ES |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 189.red-80-26-154.staticip.rima-tde.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 189.red-80-26-154.staticip.rima-tde.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 22% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 10:07:05 UTC |
| Last Seen | 2026-07-30 17:04:19 UTC |
| Profile Built | 2026-07-30 17:10:01 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.