IP Intelligence Briefing: 157.173.125.157
Date: 2026-06-12
---
**1. Risk Profile**
- Risk Score: 65/100 (Moderate Risk)
- Provider: Contabo (Cloud Compute Hosting)
- Ownership: Registered to Johannes Selg (AS: 51167, ARIN)
- Geolocation: Germany (DE), Lauterbourg, 51.17°N, 10.45°E
- Network Role: Cloud-hosted web server (HTTP/HTTPS services, HTTP/2, HSTS, CSP headers)
---
**2. Threat & Security Indicators**
- Threat Status: No direct indicators of malicious activity (no known attackers, spam, or Tor exit nodes).
- DNS Associations: Linked to mail.youplex.cc (SPF validated, no DMARC).
- TLS: Valid certificate (self-signed, issuer: www.example.org).
- Security Headers: HSTS, CSP, HTTP/2 enabled.
---
**3. Network & Subnet Analysis**
- Subnet: 157.173.125.157/24 (abuse density: 0, classified as "clean").
- Neighbors: No active or risky sibling IPs in the subnet.
- BGP: Stable route (no recent changes), RPKI valid.
---
**4. Historical Observations**
- Recent Activity (2026-06-12):
- HTTP/2 service with 200 OK responses.
- Operator score: 0.26 (Basic trust level).
- No persistent malicious activity or ownership changes.
---
**5. Recommended Actions**
- Monitoring: Increase logging verbosity for this IP.
- Firewall Rules:
- iptables: `iptables -A INPUT -s 157.173.125.157 -j DROP`
- Cloudflare WAF: Block IP with rule: `ip.src eq 157.173.125.157`
- AWS WAF: Add `157.173.125.157/32` to IP set.
---
Conclusion: This IP hosts a cloud-based web service with moderate risk. While no immediate threats are detected, its association with mail.youplex.cc and moderate risk score warrant monitoring. Apply firewall rules to restrict access and verify DNS configurations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | TT-20240614 |
| CIDR Block | 157.173.112.0/20 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | mail.youplex.cc |
| Forward Confirmed | Yes โ FCrDNS verified |
| Hosted Domain | mail.youplex.cc |
| Hosted Domain | flexxmotion.co.ke |
| Hosted Domain | www.flexxmotion.co.ke |
| Forward Hostnames | mail.youplex.cc |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-05-12T15:53:56+00:00 |
| Valid Until | 2036-05-09T15:53:56+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha512ECDSA |
| Validity Period | 3650 days |
| Serial Number | 67D316DEA20F82C96D024132CBA6B0EC400774F2 |
| Thumbprint | C59E3A57F0E50D68095B5E256433502ABDE14A73 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims AU but primary geo says DE
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-31 17:23:29 UTC |
| Last Seen | 2026-06-21 06:32:25 UTC |
| Profile Built | 2026-06-21 06:37:33 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 28 |
Full dossier details are available via our API.