IPDebrief

144.126.147.123

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 144.126.147.123

*Generated from IPDebrief data*

---

**Risk Assessment**

- Tor exit node activity detected

- Blacklisted in 1 source

- No known attacker or spam associations

- Listed as St Louis, MO, US (geoPlausible: False)

- RTT anomalies suggest potential misattribution

---

**Observation History**

- Tor exit node signals observed on 2026-06-16 (confidence: 0.95)

- 24 pulse alerts linked to Tor-related threats

- DNS resolution linked to `vmi3150148.contaboserver.net`

- BGP route stability: Stable (no recent changes)

- DNSSEC validation: Valid

---

**Relationships**

- Owned by Contabo Inc. (AS40021, CONTA-48)

- Subnet: `144.126.128.0/19`

- PTR hostname: `vmi3150148.contaboserver.net`

- DMARC record present but no SPF alignment

- No direct campaign links, but Tor exit node activity raises suspicion

---

**Neighborhood Analysis**

---

**Actionable Intelligence**

1. Monitor Tor Traffic: The IP is a Tor exit node, which could be used for anonymized malicious activity. Investigate outbound traffic patterns.

2. Verify Geolocation: The geoPlausible flag is false, suggesting potential misattribution. Cross-check with other geolocation sources.

3. Check DNS Records: The hostname `vmi3150148.contaboserver.net` is linked to Contabo, but ensure no unauthorized subdomains or misconfigurations.

4. Block Tor Exit Nodes: If this IP is not a legitimate Tor relay, consider blocking Tor exit nodes in your firewall rules.

Recommended Tools: Use `ipdebrief_actions` to generate custom firewall rules for mitigation.

---

*End of Briefing*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionMO
CitySt Louis
Timezoneβ€”
Latitude47.31
Longitude-122.26

🏒 Ownership & Registration

OrganizationContabo Inc.
ASNAS40021
Network NameCONTA-48
CIDR Block144.126.128.0/19
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRvmi3150148.contaboserver.net
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesvmi3150148.contaboserver.net

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPF0/2 domains
DMARC1/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
Tor

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
8080http-alttcpβ€”
Closed Ports25, 3389, 8443 (4 open / 7 scanned)
Servernginx/1.24.0 (Ubuntu)
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

πŸ” TLS Certificate

πŸ”’
CN=cto.maifrino.com
Issued by CN=E8, O=Let's Encrypt, C=US
Self-signed: No
SANscto.maifrino.com
Valid From2026-05-05T21:49:40+00:00
Valid Until2026-08-03T21:49:39+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number05C75A6AB55CD691800F624569E43DD8B64D
ThumbprintFC2E18A8AFC07E7D001B38A4B55F35C55B3D9407

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
27%
23
services
30%
23
ownership
35%
38
reputation
25%
13
geolocation
30%
23
Overall29%1224
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-28 16:32:07 UTC
Last Seen2026-06-29 05:35:34 UTC
Profile Built2026-06-29 05:38:13 UTC
Data FreshnessLive
Signal Types31
Total Observations59
πŸ” 31 signal types Β· 59 observations collected
This report is generated from 31+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.