# IP INTELLIGENCE BRIEFING: 80.82.70.133/32
## Executive Summary
IP address 80.82.70.133 presents a moderate risk profile (Risk Score: 55/100) with evidence of DNS blacklist listings. The IP is associated with organization IPV (ASN 202425) in the Netherlands and is currently firewalled with no active services. Recent observations indicate blacklist activity with high severity ratings.
## Ownership and Registration
- ASN: 202425 (IPV)
- Organization: IPV
- RIR: RIPE
- Geolocation: Netherlands (NL), Coordinates: 52.13°N, 5.29°E
- Timezone: Europe/Amsterdam
- CIDR Block: 80.82.70.0/24
- Registration: Abuse contact available via RDAP
## Technical Profile
- Network Role: Firewalled / No Services
- DNS Resolution: rnd.group-ib.com (forward confirmation: false)
- Email Authentication: SPF and DMARC records present
- Control Plane: BGP prefix 80.82.70.0/24, route stability: false
- DNSBL Status: Listed on 3 of 8 total lists (abuseConfidenceScore: null)
- Services: No open ports detected, no TLS certificates, no HTTP services
## Threat Indicators
- Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence: Not scored
- Known Campaigns: None identified
- Is Known Attacker: False
- Is Tor Exit: False
- Is Proxy/VPN: False
- Blacklist Count: 0 (contradicts DNSBL data)
## Historical Activity
Analysis of 19 historical observations reveals:
- 2026-06-26: Recent activity detected with 8 total blacklist listings, 2 listed with high severity
- 2026-06-06: Earlier observation showed no persistent malicious activity
- Overall: 1 threat observation recorded, not classified as persistently malicious
## Network Relationships
- Total Relationships: 29
- Network Associations: 15 instances linked to NET-1-70
- DNS Associations: 14 instances linked to rnd.group-ib.com
- Subnet Classification: Mostly clean with inherited risk of 2
## Neighborhood Analysis (80.82.70.0/24)
- Abuse Density: 0 (neighborhood shows 1)
- Classification: Mostly clean
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 1
## Recommended Actions
Immediate:
1. Increase logging verbosity and review recent activity from this IP
2. Implement blocking rules across perimeter security controls
Firewall Rules:
- iptables: `iptables -A INPUT -s 80.82.70.133 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 80.82.70.133 drop`
- nginx: `deny 80.82.70.133;`
- pfSense: `80.82.70.133/32`
- Cloudflare WAF: Block IP with risk score 55
- AWS WAF: Add 80.82.70.133/32 to IP set
## Assessment
The IP address warrants defensive monitoring due to blacklist activity and moderate risk scoring. The absence of open services suggests the IP may be used for non-public purposes or has been intentionally firewalled. Correlation with the rnd.group-ib.com domain should be verified against organizational records. No evidence of persistent malicious activity was observed in historical data.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IPV |
| ASN | AS202425 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | rnd.group-ib.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | rnd.group-ib.com |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | istio-envoy |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 21% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 08:59:28 UTC |
| Last Seen | 2026-06-26 09:18:24 UTC |
| Profile Built | 2026-06-26 10:11:58 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.