# IP Intelligence Briefing: 144.91.124.59/32
## Executive Summary
IP address 144.91.124.59 is a German-based cloud compute endpoint hosted on Contabo infrastructure. The IP presents a Moderate Risk profile (score: 40) with no active threat indicators. The endpoint is classified as "Firewalled / No Services" and shows historical stability without persistent malicious behavior.
## Ownership and Infrastructure
- Organization: Johannes Selg (CONTABO)
- ASN: 51167
- CIDR Block: 144.91.96.0/19
- Infrastructure Type: CloudCompute (Contabo)
- Geolocation: Germany (DE), Munich region
- DNS PTR: vmi1486562.contaboserver.net
## Risk Assessment
- Risk Score: 40/100 (Moderate Risk)
- Abuse Confidence: No active indicators
- Blacklist Status: 2 lists flagged out of 8 total (23% listing rate)
- Threat Classification: Not identified as Tor exit, known attacker, or spam source
- Stability: Not persistently malicious (0 threat observation days)
## Network Behavior
- Open Ports: None detected
- Service Status: Firewalled / No Services
- DNS Resolution: Forward-confirmed (1 PTR record)
- Email Reputation: No SPF/DMARC records detected on associated domain
- Route Stability: 0 route changes in 30-day window; stability flagged as false
## Neighborhood Analysis (144.91.124.0/24)
- Subnet Abuse Density: 0
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Neighbor Risk Profile: 144.91.124.133 (Risk Score: 30)
## Historical Observations
- Total Records: 18 observations
- Recent Classification: Clean (as of July 30, 2026)
- Threat Persistence: None detected
- Geolocation Validation: ICMP blocked; geolocation plausible but unvalidated
## Related Entities
- DNS Associations: vmi1486562.contaboserver.net (multiple entries)
- Network Association: CONTABO
- Transit Path: Comcast networks observed
## Recommended Security Actions
Based on the moderate risk profile (40), the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 144.91.124.59 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 144.91.124.59 drop
```
Cloudflare WAF:
```json
{
"description": "Block 144.91.124.59 β IPDebrief risk score 40",
"action": "block",
"filter": {
"expression": "ip.src eq 144.91.124.59"
}
}
```
AWS WAF:
```json
{
"Addresses": ["144.91.124.59/32"],
"Description": "IPDebrief risk 40"
}
```
## Analysis Notes
This IP represents a typical cloud hosting endpoint. The absence of open ports and lack of active threat indicators suggest benign cloud infrastructure usage. The 23% DNSBL listing rate warrants monitoring but does not indicate confirmed malicious activity. The Contabo provider classification indicates shared cloud infrastructure; correlation with 144.91.124.133 (neighbor risk score: 30) suggests moderate-risk neighborhood characteristics.
Threat Level: MODERATE β Consider blocking based on operational requirements; no immediate threat indicators detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 144.91.96.0/19 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vmi1486562.contaboserver.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vmi1486562.contaboserver.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 |
π TLS Certificate
| SANs | None |
| Valid From | 2026-08-04T17:55:45+00:00 |
| Valid Until | 2027-08-04T17:55:45+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 4647FD454913373F775DB05D0A601E013E14F05F |
| Thumbprint | 64EBF1DE3996557DD9354FBD99F0E5D37CB54A78 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 36% | 2 | 4 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 33% | 2 | 4 |
| Overall | 27% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 02:41:18 UTC |
| Last Seen | 2026-08-12 19:08:37 UTC |
| Profile Built | 2026-08-12 19:22:57 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.