IP INTELLIGENCE BRIEFING: 156.67.26.233
Classification: Low Risk / Single-Service Host
Ownership & Network Context:
The IP 156.67.26.233 belongs to Contabo (AS51167), a German VPS provider. The address is registered under organization "Johannes Selg" and is classified as a Single-Service Host. DNS PTR records resolve to vmi3105066.contaboserver.net, confirming this is a virtual machine instance.
Geolocation:
Steinen, Baden-Württemberg, Germany (DE). Geographic validation indicates plausible location with 400 km accuracy radius.
Threat Assessment:
- Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Blacklist Status: 0 blacklist entries
- Abuse Confidence: Not applicable
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Network Services:
Single port open: SSH (22/tcp). No TLS certificates or HTTP services detected. No evidence of active scanning or malicious banner patterns.
Control Plane:
BGP prefix: 156.67.24.0/22. Route stability: False. DNSSEC valid. DNSBL listed on 1 of 8 total lists (likely false positives). Operator score: 0.2609 (Basic).
Neighborhood Analysis:
Subnet 156.67.26.0/24 shows abuse density of 0 with 2 active siblings. One neighbor (156.67.26.62) shares similar risk score (25) with higher authority score (60). Classification: mostly clean.
Observation History:
22 observations recorded. Most recent activity on 2026-06-20. Signals show consistent classification as Contabo infrastructure. No evidence of escalating threat behavior or persistent malicious activity. Threat observation count: 1.
Relationships:
39 relationships identified. Primary associations include DNS hostname vmi3105066.contaboserver.net and network identifier TT-20240409.
Recommended Actions:
- No immediate blocking recommended based on current risk profile
- Monitor for escalation in risk score or new threat indicators
- Standard VPS traffic monitoring applies
- If used as attack source, monitor associated hostname for correlation
Summary:
This IP represents a standard Contabo VPS with minimal threat indicators. The low risk score, clean neighborhood profile, and absence of threat campaign associations indicate this is a legitimate hosting resource rather than a malicious endpoint. SOC teams may apply standard monitoring without elevated alerting.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3105066.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3105066.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | โ |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 22:12:10 UTC |
| Last Seen | 2026-06-28 12:35:10 UTC |
| Profile Built | 2026-06-29 06:40:15 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.