# IP Intelligence Briefing: 161.97.184.113/32
## Executive Summary
IP address 161.97.184.113 presents a Moderate Risk profile (Risk Score: 40) associated with CONTABO hosting infrastructure in Germany. The IP operates as a web server (Apache/2.4.37 on Rocky Linux) with no active threat indicators but exhibits DNSBL listings on 2 of 8 threat feeds. Recommended mitigation is blocking at the perimeter firewall.
---
## Technical Profile
Network & Ownership
- ASN: 51167 (CONTABO)
- Organization: Johannes Selg
- CIDR Block: 161.97.184.0/22
- RIR: ARIN
Geolocation
- Country: Germany (DE)
- Coordinates: 51.17, 10.45 (Europe/Berlin timezone)
- Geo Validation: Plausible (RtT: 110-120ms average)
Services & Ports
| Port | Protocol | Service | Banner |
|---|---|---|---|
| 80 | TCP | HTTP | Apache/2.4.37 (Rocky Linux) OpenSSL/1.1.1k |
| 443 | TCP | HTTPS | Apache/2.4.37 (Rocky Linux) OpenSSL/1.1.1k |
| 22 | TCP | SSH | SSH-2.0-OpenSSH_8.0 |
DNS Analysis
- PTR Hostname: vmi2531376.contaboserver.net
- Forward Resolution: vmi2531376.contaboserver.net (forward confirmed)
- TLS Certificate: Self-signed (E=root@issabel.local, CN=issabel.local, OU=PBX, O=Issabel)
- Security Posture: SPF and DMARC not configured
---
## Threat Assessment
Risk Indicators
- Risk Score: 40/100 (Moderate)
- DNSBL Listings: 2 of 8 threat feeds
- Abuse Confidence Score: Not assigned
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Status
- Route Stability: Flagged as unstable
- RPKI State: Not validated
- DNSSEC: Valid
---
## Historical Observations
Total signals collected: 22 observations
Most recent activity (2026-08-06):
- Geolocation consistent with Germany (401.9km from probe location)
- HTTP/HTTPS services responding normally (200 status code)
- Server fingerprint: Apache/2.4.37, PHP/7.4.33
- No persistent malicious activity detected
- Threat observation count: 1 (transient)
---
## Network Neighborhood Analysis
Subnet: 161.97.184.113/24
- Abuse Density: 0.5 (moderate)
- Classification: mostly_clean
- Total Siblings: 2 active siblings
- Threat Siblings: 1
- Neighbor Risk Distribution: 1 low, 0 medium, 0 high
Notable Neighbor:
- 161.97.184.127: Risk Score 0, Authority Score 60 (clean profile)
---
## Relationships
- Network Association: CONTABO
- DNS Associations: vmi2531376.contaboserver.net (multiple entries)
- Total Relationships: 8 identified
---
## Recommended Security Actions
Firewall Rules (Recommended)
| System | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 161.97.184.113 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 161.97.184.113 drop` |
| nginx | `deny 161.97.184.113;` |
| pfSense | `161.97.184.113/32` |
| Cloudflare WAF | Block โ IPDebrief risk score 40 |
| AWS WAF | `Addresses: ["161.97.184.113/32"]` |
Mitigation Notes
- DNSBL presence indicates prior reputation issues
- Self-signed TLS certificate suggests limited security hygiene
- Route instability may indicate hosting provider issues
- No active attack indicators; block recommendation is precautionary
---
Classification: Moderate Risk โ Monitor or Block Based on Policy
Last Updated: 2026-08-06
Data Sources: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 161.97.184.0/22 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi2531376.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi2531376.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | Apache/2.4.37 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 30% | 10 | 17 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims -- but primary geo says DE
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-04 05:42:25 UTC |
| Last Seen | 2026-08-13 06:03:56 UTC |
| Profile Built | 2026-08-13 06:21:22 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.