# IP Intelligence Briefing: 169.58.39.191/32
Date: 2026-08-12
Classification: Low Risk Infrastructure Asset
## Executive Summary
The IP 169.58.39.191 presents a low-risk profile suitable for continued network traffic analysis. This address operates as a Contabo cloud hosting VMI (Virtual Machine Instance) with standard web and SSH services. While the IP itself carries no direct threat indicators, the /24 neighborhood exhibits moderate abuse density with one flagged threat sibling.
## Infrastructure Profile
- Organization: Johannes Selg
- ASN: 51167 (Contabo)
- Netname: TT-20260630
- Geolocation: Germany (51.17, 10.45) โ Europe/Berlin timezone
- Server Type: Microsoft-IIS/10.0 with ASP.NET application framework
- DNS Resolution: vmi3450108.contaboserver.net (VMI identifier)
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| Overall Risk Score | 0 | Low Risk |
| Provider Score | 0 | No Provider-Related Threats |
| Authority Score | 0 | No Abuse History |
| Blacklist Count | 0 | Clean Reputation |
| Abuse Confidence | N/A | No Malicious Activity |
## Neighborhood Analysis
The /24 subnet (169.58.39.0/24) shows:
- Abuse Density: 0.3333 (33.33%)
- Subnet Classification: Mostly Clean
- Active Siblings: 2 of 3 total IPs
- Threat Siblings: 1 flagged as malicious
Notable Neighbors:
- 169.58.39.117: Risk Score 50, Authority Score 60
- 169.58.39.161: Risk Score 65, Authority Score 60
## Historical Observations
Analysis of 25 historical observations indicates stable operational characteristics:
- Ownership changes: None recorded
- Threat persistence: None (0 threat observation days)
- Route stability: False (minor BGP instability noted)
- Operator classification: Basic (0.2609 score)
## Service Exposure
- Port 80 (HTTP): Open โ Web application serving (IIS)
- Port 22 (SSH): Open โ Remote administration available
- TLS: No certificate detected (port 443 not confirmed)
## Operational Context
The IP functions as a standard multi-service host within Contabo's cloud infrastructure. The hostname pattern (vmi* + contaboserver.net) confirms VMI hosting. No evidence of proxy, VPN, CDN, or residential proxy services.
## Recommendations
1. Monitoring Priority: Medium โ Neighborhood abuse density warrants continued surveillance
2. Firewall Action: No immediate blocking required; standard allow policies appropriate
3. Threat Context: Monitor for correlation with flagged neighbor 169.58.39.161 (Risk Score 65)
4. Geographic Considerations: Traffic from Germany/Europe; ensure appropriate geo-filters if regionally scoped
## Conclusion
IP 169.58.39.191 is not a direct threat actor. The low-risk profile combined with standard hosting services suggests legitimate infrastructure use. However, the 33.33% neighborhood abuse density indicates the broader subnet requires periodic review. SOC teams should monitor for any changes in threat indicators or correlation with neighboring malicious IPs.
---
*Report generated from IPDebrief intelligence platform data.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | TT-20260630 |
| CIDR Block | 169.58.0.0/17 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3450108.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3450108.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | โ |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Microsoft-IIS/10.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 29% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 07:15:33 UTC |
| Last Seen | 2026-08-12 16:40:25 UTC |
| Profile Built | 2026-08-12 16:54:24 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.