# IP INTELLIGENCE BRIEFING: 91.80.156.154/32
## Executive Summary
The IP address 91.80.156.154 presents a moderate risk profile (risk score: 40/100) with ambiguous geolocation data and no active threat indicators. The IP is classified as "Firewalled / No Services" with no open ports detected. Recommended defensive blocking is available but should be validated against organizational policies.
---
## Risk Assessment
- Overall Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not reported
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Threat Classification: Not flagged as known attacker, spam source, or Tor exit node
- Campaign Association: No known threat campaigns linked
---
## Geolocation & Network Infrastructure
Primary Location Data (from historical observations):
- Country: Italy (IT) / United States (US) - conflicting data
- City: Ivrea (TO) / New York, NY
- ASN: 30722 (Origin)
- BGP Prefix: 91.80.128.0/17
- Organization: Vodafone Italy (RIPE registry)
- Abuse Contact: abuse@fastweb.it
Network Characteristics:
- Traceroute: 17 hops, 104.3ms final hop RTT, 4 timed-out hops
- First Hop: Comcast network
- Route Stability: False (non-MOAS, isRouteStable: false)
- RPKI State: Not validated
- ISP Classification: Not classified as provider/CDN/VPN/proxy
---
## Observational History
- Total Observations: 13 signals
- Most Recent: 2026-07-29
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
Recent observations indicate:
- RIR: RIPE (confidence: 0.90)
- Network: Vodafone Italy (confidence: 0.95)
- Geographic: Italy (confidence: 0.35)
---
## Subnet & Neighborhood Analysis
Subnet: 91.80.156.154/24
- Abuse Density: 0
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
Neighboring IP: 91.80.156.226
- Risk Score: 0 (Low)
- Authority Score: 50
- Classification: Clean subnet
---
## Defensive Actions & Recommendations
Recommended Firewall Rules (based on risk score 40):
| System | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 91.80.156.154 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 91.80.156.154 drop` |
| nginx | `deny 91.80.156.154;` |
| pfSense | `91.80.156.154/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 91.80.156.154` |
| AWS WAF | Add to allowed/denied addresses list: `91.80.156.154/32` |
Note: Recommendations are probabilistic and should be combined with other signals before taking action.
---
## Key Observations & Anomalies
1. Geolocation Conflict: Profile shows US/New York while historical data indicates Italy/Ivrea. Multiple geolocation sources report conflicting results.
2. Low Activity Profile: No open ports, no active services, no TLS certificates, no DNS resolution.
3. Clean Neighborhood: Only one sibling IP in /24 subnet with low risk score.
4. DNSBL Presence: Listed on 2 of 8 DNSBLs without active threat indicators.
5. Route Instability: Control plane indicates route is not stable (non-MOAS).
---
## Threat Intelligence Narrative
IP 91.80.156.154 is a low-activity address with no current malicious indicators. The moderate risk classification stems from DNSBL listings and geolocation inconsistencies rather than active threat behavior. The subnet demonstrates clean characteristics with minimal abuse density. Historical data shows consistent ownership under Vodafone Italy (RIPE) infrastructure. Current routing through Comcast suggests potential multi-tier hosting or proxy infrastructure. No evidence of active attacks, scanning, or exploitation campaigns. Defensive blocking may be appropriate for high-security environments, but traffic analysis should be considered to determine if legitimate use cases exist.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Vodafone Italy |
| ASN | AS30722 |
| Network Name | VODAFONE-IT-21 |
| CIDR Block | 91.80.128.0/17 |
| RIR | RIPE |
| Country | IT |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 08:19:14 UTC |
| Last Seen | 2026-07-29 23:01:41 UTC |
| Profile Built | 2026-07-29 23:11:13 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.