IPDebrief

80.82.76.41

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 80.82.76.41

Classification: Moderate Risk (Score: 59/100) | Date: Current | Status: Active Threat Indicator

---

## Executive Summary

IP 80.82.76.41 presented as a moderate-risk address associated with Tor exit node infrastructure in Amsterdam, Netherlands. The IP exhibited threat indicators and was listed on one DNS blacklist. Recommended action includes enhanced monitoring and consideration of traffic blocking.

---

## Technical Profile

---

## Threat Indicators

---

## Network Behavior

- Port 80/TCP (HTTP)

- Port 443/TCP (HTTPS)

- Port 22/TCP (SSH - OpenSSH_10.0p2 Debian-7+deb13u4)

---

## Observation History

---

## Subnet Context (80.82.76.0/24)

---

## Recommended Actions

Immediate Mitigation

1. Access Control: Consider enhanced verification for anonymous traffic from this IP

2. Monitoring: Increase logging verbosity and review recent activity from 80.82.76.41

Firewall Implementation

```bash

# iptables

iptables -A INPUT -s 80.82.76.41 -j DROP

# nftables

nft add rule inet filter input ip saddr 80.82.76.41 drop

# nginx

deny 80.82.76.41;

# pfSense

80.82.76.41/32

# Cloudflare WAF

{"description":"Block 80.82.76.41 — IPDebrief risk score 59","action":"block","filter":{"expression":"ip.src eq 80.82.76.41"}}

# AWS WAF

{"Addresses":["80.82.76.41/32"],"Description":"IPDebrief risk 59"}

```

---

## Analysis Notes

The IP address is classified as a Tor exit node, which is consistent with the observed threat indicators. The moderate risk score (59/100) reflects the Tor association and single DNSBL listing. The subnet shows minimal abuse density overall, suggesting this IP operates with some degree of isolation from broader subnet malicious activity. Route instability was observed, indicating potential infrastructure changes in the past 30 days.

Recommendation: Implement blocking rules while maintaining monitoring for any legitimate business justification for this IP. Review TLS certificate subject (www.hxdpteet6jqllz.net) against threat intelligence feeds for additional context.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇳🇱 Netherlands
RegionNH
CityAmsterdam
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

🏢 Ownership & Registration

OrganizationIPV
ASNAS202425
Network NameNET-1-76
CIDR Block80.82.76.0/25
RIRRIPE
CountryNL
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR41.76.82.80.in-addr.arpa
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames41.76.82.80.in-addr.arpa

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

An expired certificate for CN=www.yhzonbyawozlp.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
🔒
CN=www.yhzonbyawozlp.net
Issued by CN=www.tccyzdkd342cy.com
Self-signed: No
SANsNone
Valid From2026-07-28T00:00:00+00:00
Valid Until2026-09-26T23:59:59+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period60 days

🛡️ Public Network Snapshot

Origin ASNAS202425
Network Prefix80.82.76.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
20%
24
routing
17%
23
services
24%
23
ownership
19%
34
reputation
16%
13
geolocation
20%
23
Overall19%1220
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-04 22:50:11 UTC
Last Seen2026-08-26 19:13:16 UTC
Profile Built2026-08-29 07:39:29 UTC
Data FreshnessLive
Signal Types28
Total Observations29
🔍 28 signal types · 29 observations collected
This report is generated from 28+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 80.82.76.41

Who owns the IP address 80.82.76.41?

80.82.76.41 is registered to IPV. The address falls within the 80.82.76.0/25 network block. Registration is held at RIPE.

Where is 80.82.76.41 located?

Geolocation data places 80.82.76.41 in Amsterdam, NH, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 80.82.76.41 malicious or safe?

80.82.76.41 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 80.82.76.41?

The reverse DNS (PTR) record for 80.82.76.41 is 41.76.82.80.in-addr.arpa. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 80.82.76.41?

Responsive ports observed on 80.82.76.41 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.