IPDebrief

91.80.131.143

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 91.80.131.143/32

## EXECUTIVE SUMMARY

IP address 91.80.131.143 is a mobile carrier endpoint from Vodafone Italia with a moderate risk score of 55/100. The IP shows no active services, no open ports, and limited network reputation. Historical data indicates threat indicators have been observed. Recommended action is monitoring and selective blocking depending on organizational policy.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
ASNAS30722 (Vodafone Italia S.p.A.)
OrganizationVodafone Italy (VODAFONE-IT-21)
CIDR Block91.80.128.0/17
CountryItaly (IT)
Region36 (Veneto)
CitySacile
Network TypeMobile Carrier (LTE/5G)

The IP belongs to Vodafone Italia's mobile network infrastructure. No dedicated hosting or CDN infrastructure detected. The subnet 91.80.131.143/24 shows zero abuse density with no neighboring IPs flagged for abuse.

---

## THREAT INTELLIGENCE

IndicatorStatus
Risk Score55/100 (Moderate Risk)
Blacklist Count3 DNSBL listings
Threat FeedsNone directly flagged
Tor Exit NodeNo
Known AttackerNo
Spam SourceNo
Known CampaignsNone correlated

The IP shows 3 DNSBL listings across 8 total lists. Control plane analysis indicates minimal operator score (0.1304) with stable routing (no route changes in 30 days).

---

## NETWORK BEHAVIOR

The endpoint appears to be a legitimate mobile device without exposed services. No HTTP banner, server fingerprint, or email reputation data available.

---

## OBSERVATION HISTORY

15 total observations recorded. Recent activity (2026-07-29) confirms:

The IP has no persistent malicious designation but shows elevated risk due to DNSBL listings and historical threat indicators.

---

## RELATIONSHIPS

---

## RECOMMENDED ACTIONS

Primary Recommendation: Increase logging verbosity and review recent activity from this IP (High Severity due to elevated risk score).

Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 91.80.131.143 -j DROP

# nftables

nft add rule inet filter input ip saddr 91.80.131.143 drop

# nginx

deny 91.80.131.143;

# pfSense

91.80.131.143/32

# Cloudflare WAF

ip.src eq 91.80.131.143 โ†’ BLOCK

# AWS WAF

Addresses: ["91.80.131.143/32"]

```

---

## SOC ANALYST NOTES

1. Block or Monitor Decision: Given the moderate risk score (55) and mobile carrier origin, consider blocking only if the organization receives traffic from unexpected geographic regions or during unusual hours.

2. False Positive Risk: Legitimate mobile traffic may appear from this IP range. Verify against organizational baseline before implementing permanent blocking.

3. Monitoring Priority: Track for any changes in traffic patterns, geolocation shifts, or new threat indicators.

4. Subnet Context: No abuse activity detected in the /24 subnet. This IP appears isolated from broader subnet-level threats.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡น Italy
Region36
CitySacile
TimezoneEurope/Rome
Latitude45.95
Longitude12.50

๐Ÿข Ownership & Registration

OrganizationVodafone Italy
ASNAS30722
Network NameVODAFONE-IT-21
CIDR Block91.80.128.0/17
RIRRIPE
CountryIT
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
22
routing
25%
11
services
25%
11
ownership
0%
00
reputation
25%
11
geolocation
0%
00
Overall18%55
Coverage: 4/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-24 08:19:14 UTC
Last Seen2026-07-29 23:01:31 UTC
Profile Built2026-07-29 23:11:13 UTC
Data FreshnessLive
Signal Types19
Total Observations19
๐Ÿ” 19 signal types ยท 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.