# IP Intelligence Briefing: 164.68.124.190/32
Classification: Low Risk
Risk Score: 25/100
Last Updated: Current Intelligence Cycle
---
## Executive Summary
IP address 164.68.124.190 is a Contabo cloud infrastructure endpoint located in Lauterbourg, France, associated with organization "Johannes Selg" (ASN: 51167). The IP demonstrates minimal threat indicators with a low-risk classification. No malicious activity or attack patterns detected in observation history. Recommended classification for monitoring rather than blocking.
---
## Technical Profile
Infrastructure:
- Provider: Contabo (CloudCompute)
- Network Role: Single-Service Host
- ASN: 51167
- BGP Prefix: 164.68.124.0/23
- Route Stability: Unstable (isRouteStable: false)
Geolocation:
- Country: Germany (DE)
- Region: Grand Est
- City: Lauterbourg
- Coordinates: 51.17°N, 10.45°E
- Timezone: Europe/Berlin
DNS Resolution:
- Forward Hostname: vmi3300870.contaboserver.net
- PTR Record: vmi3300870.contaboserver.net
- Forward Confirmed: Yes
- Email Authentication: SPF/DMARC not configured
---
## Threat Indicators
Current Threat Assessment:
- Reputation: Low Risk
- Abuse Confidence Score: Not Available
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None
Blacklist Status:
- DNSBL Lists Listed: 1 of 8
- Total Abuse Confidence: Low
Network Classification Flags:
- Cloud Infrastructure: Yes
- CDN: No
- VPN/Proxy: No
- Hosting: Yes
- Residential: No
- Bogon: No
---
## Service Exposure
Open Services Detected:
- Port 22/TCP: SSH (OpenSSH_9.6p1 Ubuntu-3ubuntu13.16)
Web Services:
- HTTP Title: None
- TLS Certificate: Not Present
---
## Neighborhood Analysis
Subnet: 164.68.124.190/24
- Abuse Density: 1 (mostly_clean)
- Inherited Risk: 5/100
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 2
Adjacent IP Assessment:
- 164.68.124.118: Risk Score 25, Authority Score 60
---
## Observation History
Signal Count: 22 observations tracked
Temporal Analysis:
- Recent observations (June 2026) show consistent minimal risk signals
- Ownership changes: None detected
- Threat persistence days: 0
- Is persistently malicious: No
Signal Types Observed:
- Network classification signals
- Geolocation inference signals
- Provider identification signals
- Minimal threat indicator signals
---
## Relationship Graph
Key Associations (58 relationships):
- Contabo Network: Multiple "Same Network" links
- DNS Hostnames: vmi3300870.contaboserver.net (DNS Association)
- Network Infrastructure: Contabo cloud provider relationships
---
## Recommended Security Actions
Firewall/Blocking Decision:
- Action: Monitor / Allow with logging
- Risk Justification: Low risk score (25/100), no malicious indicators, legitimate cloud provider infrastructure
Actionable Rules:
- No blocking recommended based on current risk profile
- Consider rate limiting on SSH port 22 if exposing to internet
- Monitor for unusual outbound connections
---
## Intelligence Conclusions
IP 164.68.124.190 represents a legitimate Contabo cloud computing endpoint with no evidence of malicious activity. The low risk score, clean neighborhood context, and absence of threat indicators support classification as benign infrastructure. No immediate action required beyond standard monitoring practices.
Threat Level: LOW
Recommended Disposition: ALLOW (with monitoring)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3300870.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3300870.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:50 UTC |
| Last Seen | 2026-06-27 01:10:43 UTC |
| Profile Built | 2026-06-27 21:23:31 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.