IP INTELLIGENCE BRIEFING: 109.123.244.125/32
---
CLASSIFICATION: LOW RISK / MONITOR
SUMMARY:
IP 109.123.244.125 is a cloud-hosted web server operated by Contabo (AS51167) in Lauterbourg, Germany (DE). The asset maintains a Low Risk reputation score of 25/100 and demonstrates consistent operational characteristics across 23 historical observations. No malicious threat indicators were identified.
---
INFRASTRUCTURE PROFILE:
- Provider: Contabo (CloudCompute infrastructure)
- ASN: 51167
- Geolocation: Grand Est, DE (coordinates: 51.17°N, 10.45°E)
- Network Classification: Cloud hosting, web server
- DNS Resolution: vmi3319189.contaboserver.net (forward confirmed)
- TLS Certificate: Let's Encrypt (CN=metronanalytic.com)
---
THREAT ASSESSMENT:
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: Listed on 1 of 8 DNSBL checks
- Known Threat Indicators: None detected
- Campaign Correlation: No associated campaigns or correlated IPs
- Threat Persistence: 0 days (not persistently malicious)
OPEN SERVICES:
- Port 80/tcp (HTTP) - nginx/1.24.0
- Port 443/tcp (HTTPS) - nginx/1.24.0
- Port 22/tcp (SSH) - OpenSSH_9.6p1 Ubuntu
---
HISTORICAL OBSERVATIONS:
23 signal observations collected. Profile shows consistent cloud hosting characteristics with minimal changes over time. Recent observations confirm:
- Provider identification stable (Contabo)
- Infrastructure type: CloudCompute
- No transitions to Tor, VPN, or proxy services
- DNSSEC validation present
---
NETWORK RELATIONSHIPS:
49 relationships identified:
- DNS associations to vmi3319189.contaboserver.net (multiple records)
- Network associations to TT-20221020
SUBNET ANALYSIS (109.123.244.0/24):
- Abuse Density: 0 (mostly_clean classification)
- Neighbor Count: 1 active sibling (109.123.244.82, Risk Score: 30)
- Inherited Risk: 5/100
---
RECOMMENDATIONS:
Firewall/Network Controls:
- No blocking required based on current risk profile
- Monitor DNSBL listing status (currently listed on 1 of 8 feeds)
- SSH port 22 accessible from internet โ implement rate limiting if not required
Email Security:
- SPF record present (check validity)
- DMARC record missing โ recommend configuration for domain metronanalytic.com
Monitoring:
- Continue standard monitoring for cloud hosting infrastructure
- No immediate threat action required
- Review DNSBL listing periodically
RISK RATING: LOW
ACTION: CONTINUE MONITORING / NO IMMEDIATE ACTION REQUIRED
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3319189.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3319189.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | metronanalytic.comwww.metronanalytic.com |
| Valid From | 2026-06-03T14:28:01+00:00 |
| Valid Until | 2026-09-01T14:28:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 058C61B99A8798B2E55AE073C54780DE6E1D |
| Thumbprint | A018C720CC9A0ECF816A2A21474566EFB4023F08 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 26% | 2 | 2 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 06:31:54 UTC |
| Last Seen | 2026-06-28 23:35:43 UTC |
| Profile Built | 2026-06-29 05:35:57 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.