# IP Intelligence Briefing: 167.86.67.211/32
Date: Current
Status: Moderate Risk (Score: 40/100)
Classification: Cloud Compute Infrastructure
---
## Executive Summary
The IP address 167.86.67.211 is a Contabo cloud computing virtual private server located in Nuremberg, Germany (ASN 51167). The address shows no current active threat indicators but maintains a moderate risk profile due to DNSBL listings on 2 of 8 threat intelligence feeds. No open services or ports were detected during analysis.
---
## Infrastructure Profile
- Organization: Johannes Selg (Contabo GmbH)
- Infrastructure Type: CloudCompute / VPS
- Geolocation: Nuremberg, Germany (51.17°N, 10.45°E)
- Network Block: 167.86.66.0/23
- Reverse DNS: vmi2590711.contaboserver.net
- Forward DNS: vmi3374842.contaboserver.net
---
## Threat Indicators
- Risk Score: 40/100 (Moderate)
- Blacklist Count: 2 of 8 threat feeds
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Scans: None detected
- Threat Persistence: Not observed
---
## Historical Analysis
Analysis of 25 historical observations revealed inconsistent geolocation reporting. One observation flagged proxy/VPN activity with a risk score of 66 from proxycheck-io, reporting France (Paris) as the origin. Current geolocation reports Germany (Nuremberg) with an average RTT of 119ms and 464.5km distance from probe origin. No persistent malicious activity was detected across the observation timeline.
---
## Neighborhood Assessment
The /24 subnet (167.86.67.0/24) demonstrates low abuse density:
- Total Siblings: 256 IPs
- Active Siblings: 1
- Threat Siblings: 2
- Abuse Density: 0 (mostly clean)
- Neighbor Risk Scores: 25 and 0 (both low)
Two neighboring IPs were detected: 167.86.67.121 (Risk: 25) and 167.86.67.147 (Risk: 0).
---
## Related Entities
- Primary Network: CONTABO
- DNS Associations: Multiple contaboserver.net hostnames
- Operator Score: 0.2609 (Basic)
- Route Stability: Not stable
- RPKI State: Not verified
---
## Recommended Actions
- Block: Consider blocking at perimeter firewall if traffic patterns indicate potential abuse
- Monitor: Maintain monitoring due to DNSBL listings
- Investigate: Review traffic logs for outbound connections from this IP
- Context: Treat as legitimate cloud infrastructure unless malicious behavior is observed
---
Conclusion: This IP represents standard Contabo cloud infrastructure with moderate risk due to DNSBL listings. No immediate blocking required unless specific malicious activity is observed in traffic logs.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi2590711.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3374842.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 13:23:49 UTC |
| Last Seen | 2026-06-28 00:48:54 UTC |
| Profile Built | 2026-06-28 18:54:16 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.