# IP Intelligence Briefing: 80.82.76.41
Classification: Moderate Risk (Score: 59/100) | Date: Current | Status: Active Threat Indicator
---
## Executive Summary
IP 80.82.76.41 presented as a moderate-risk address associated with Tor exit node infrastructure in Amsterdam, Netherlands. The IP exhibited threat indicators and was listed on one DNS blacklist. Recommended action includes enhanced monitoring and consideration of traffic blocking.
---
## Technical Profile
- IP Address: 80.82.76.41/32
- ASN: 202425 (IPV)
- Organization: IPV
- Network Block: 80.82.76.0/25
- Geolocation: Netherlands (NL), Amsterdam
- Reputation Score: 59 (Moderate Risk)
- Risk Classification: Tor Exit Node infrastructure
---
## Threat Indicators
- Tor Exit Node Indicators: Observed
- DNSBL Listings: 1 of 8 total lists (severity: high)
- Blacklist Count: 1
- Known Campaigns: None identified
- Is Known Attacker: No
- Is Spam Source: No
---
## Network Behavior
- Open Services:
- Port 80/TCP (HTTP)
- Port 443/TCP (HTTPS)
- Port 22/TCP (SSH - OpenSSH_10.0p2 Debian-7+deb13u4)
- TLS Certificate: CN=www.nmvbb5vby4.com (subject: CN=www.hxdpteet6jqllz.net)
- Control Plane: BGP prefix 80.82.76.0/24, route stability: unstable (1 route change in 30 days)
- Ownership: Stable (0 ownership changes observed)
---
## Observation History
- Total Signals: 77 observations
- Recent Activity: Multiple threat signals observed July 23, 2026
- Threat Persistence: No persistent malicious activity detected
- DNS Listings: 1 listing with maximum severity: high
---
## Subnet Context (80.82.76.0/24)
- Abuse Density: 0 (mostly clean classification)
- Risk Distribution: No high or medium risk neighbors identified
- Threat Siblings: 1 threat sibling within subnet
- Active Siblings: 1 active IP in subnet
---
## Recommended Actions
Immediate Mitigation
1. Access Control: Consider enhanced verification for anonymous traffic from this IP
2. Monitoring: Increase logging verbosity and review recent activity from 80.82.76.41
Firewall Implementation
```bash
# iptables
iptables -A INPUT -s 80.82.76.41 -j DROP
# nftables
nft add rule inet filter input ip saddr 80.82.76.41 drop
# nginx
deny 80.82.76.41;
# pfSense
80.82.76.41/32
# Cloudflare WAF
{"description":"Block 80.82.76.41 — IPDebrief risk score 59","action":"block","filter":{"expression":"ip.src eq 80.82.76.41"}}
# AWS WAF
{"Addresses":["80.82.76.41/32"],"Description":"IPDebrief risk 59"}
```
---
## Analysis Notes
The IP address is classified as a Tor exit node, which is consistent with the observed threat indicators. The moderate risk score (59/100) reflects the Tor association and single DNSBL listing. The subnet shows minimal abuse density overall, suggesting this IP operates with some degree of isolation from broader subnet malicious activity. Route instability was observed, indicating potential infrastructure changes in the past 30 days.
Recommendation: Implement blocking rules while maintaining monitoring for any legitimate business justification for this IP. Review TLS certificate subject (www.hxdpteet6jqllz.net) against threat intelligence feeds for additional context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IPV |
| ASN | AS202425 |
| Network Name | NET-1-76 |
| CIDR Block | 80.82.76.0/25 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 41.76.82.80.in-addr.arpa |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 41.76.82.80.in-addr.arpa |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
CN=www.yhzonbyawozlp.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2026-07-28T00:00:00+00:00 |
| Valid Until | 2026-09-26T23:59:59+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 60 days |
🛡️ Public Network Snapshot
| Origin ASN | AS202425 |
| Network Prefix | 80.82.76.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 24% | 2 | 3 |
| ownership | 19% | 3 | 4 |
| reputation | 16% | 1 | 3 |
| geolocation | 20% | 2 | 3 |
| Overall | 19% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-04 22:50:11 UTC |
| Last Seen | 2026-08-26 19:13:16 UTC |
| Profile Built | 2026-08-29 07:39:29 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 80.82.76.41
Who owns the IP address 80.82.76.41?
80.82.76.41 is registered to IPV. The address falls within the 80.82.76.0/25 network block. Registration is held at RIPE.
Where is 80.82.76.41 located?
Geolocation data places 80.82.76.41 in Amsterdam, NH, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 80.82.76.41 malicious or safe?
80.82.76.41 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 80.82.76.41?
The reverse DNS (PTR) record for 80.82.76.41 is 41.76.82.80.in-addr.arpa. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 80.82.76.41?
Responsive ports observed on 80.82.76.41 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.