# IP INTELLIGENCE BRIEFING
Target: 144.91.71.84/32
Classification: LOW RISK
Date: Current Analysis
## Executive Summary
IP address 144.91.71.84 is a Contabo cloud infrastructure endpoint with no observed malicious activity. The address shows a risk score of 0 and zero blacklist associations. Historical analysis indicates consistent benign classification with no escalation patterns. No immediate security actions are required.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 144.91.71.84/32 |
| **ASN** | AS51167 (Contabo) |
| **Organization** | Johannes Selg (CONTABO) |
| **CIDR Block** | 144.91.64.0/19 |
| **Country** | DE (Germany) |
| **Infrastructure Type** | CloudCompute (VPS) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Risk Score** | 0 |
---
## Technical Indicators
DNS Resolution:
- Primary Hostname: `vmi3340808.contaboserver.net`
- Forward Resolution: Confirmed
- Hosted Domain Count: 0
Network Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- Service Status: Firewalled / No Services
Threat Indicators:
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Associations: None
---
## Neighborhood Analysis
Subnet Assessment: 144.91.71.84/24
- Abuse Density: 0%
- Classification: Clean
- Threat Siblings: 0
- Active Siblings: 0
- Risk Distribution: Zero across all severity levels
The /24 subnet demonstrates no concentration of malicious activity, supporting the clean classification of the target IP.
---
## Historical Observation
Total Observations: 18 signals tracked
Temporal Pattern:
- Classification: Consistently "clean"
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Is Persistently Malicious: No
Historical data shows no degradation in reputation or emergence of threat indicators. The IP has maintained stable benign behavior throughout the observation window.
---
## Relationship Graph
Associated Entities:
- DNS Hostname: vmi3340808.contaboserver.net (contaboserver.net)
- Network: CONTABO (144.91.64.0/19)
No additional relationships to external threat actors, campaigns, or infrastructure were identified.
---
## Security Recommendations
Action: NO ACTION REQUIRED
Rationale: The IP address presents no observable threat indicators. Recommended firewall rules are not applicable based on current risk profile. Standard network monitoring continues.
---
## Intelligence Assessment
This IP address represents standard commercial cloud infrastructure from Contabo, a legitimate hosting provider. The hostname pattern (vmi3340808.contaboserver.net) confirms VPS hosting usage. With zero threat indicators, clean neighborhood metrics, and consistent historical behavior, this endpoint is classified as benign. No blocking or monitoring escalation is warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 144.91.64.0/19 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3340808.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3340808.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 24% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-03 11:21:55 UTC |
| Last Seen | 2026-08-13 04:52:18 UTC |
| Profile Built | 2026-08-13 05:05:27 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.