IP Intelligence Briefing: 161.97.94.188
Date: 2026-06-08
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Registered to Johannes Selg (AS51167, Contabo).
- Geolocation: Germany (Lauterbourg, Grand Est region), coordinates 51.17°N, 10.45°E.
- Network Role: CloudCompute infrastructure (Contabo provider).
- Threat Indicators: No malicious activity detected (no indicators, blacklists, or campaigns).
- DNS: Resolves to `vmd196548.contaboserver.net` (Contabo-hosted).
---
**2. Observation History**
- Latest Activity (2026-06-08):
- Geolocation confirmed in Germany (400m accuracy radius).
- Network classification: Contabo CloudCompute.
- Operator score: "Basic" (DNSSEC valid, no CAA records).
- Historical Context (2026-05-31):
- Confirmed as a cloud-hosted instance (no residential/mobile/VPN/CDN).
- No changes in ownership or threat signals.
---
**3. Network Relationships**
- Linked Entities:
- Contabo (same network/ISP).
- DNS Hostname: `vmd196548.contaboserver.net` (Contabo infrastructure).
- Notable:
- No connections to Tor, VPNs, or malicious domains.
- One DNS resolution error (timeout to `192.168.2.108#53`) likely noise.
---
**4. Subnet Analysis**
- Subnet: 161.97.94.188/24
- Abuse Density: 0% (clean subnet).
- Neighbors: No active IPs in the subnet (likely a single-host /32 CIDR).
---
**5. Recommendations**
- No Immediate Action Required: Low risk, no malicious indicators, and no network anomalies.
- Monitor: Track for unexpected geolocation changes or new DNS associations.
- Firewall: No blocking rules needed; allow traffic unless specific services are identified.
Conclusion: Legitimate Contabo CloudCompute instance with no threat indicators. No further action required unless new activity emerges.
---
*Generated via IPDebrief intelligence tools (profile, history, relationships, neighbors).*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | 161.97.94.0/23 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmd196548.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmd196548.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.29.8 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | pulse.offground.solutions |
| Valid From | 2026-04-30T19:47:13+00:00 |
| Valid Until | 2026-07-29T19:47:12+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 06A88F6AE1DCBABBE17C420207F6E305706B |
| Thumbprint | BEE16EC523FCEA3DB927D4B7E842A4EA9330D354 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 39% | 2 | 3 |
| services | 29% | 2 | 4 |
| ownership | 35% | 3 | 5 |
| reputation | 24% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 30% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-17 03:07:42 UTC |
| Last Seen | 2026-06-28 04:17:36 UTC |
| Profile Built | 2026-06-28 22:22:34 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 32 |
Full dossier details are available via our API.