IP Intelligence Briefing: 173.212.233.81/32
Date: 2026-06-01
---
**1. Risk Profile**
- Risk Score: 80 (High Risk)
- Provider: Contabo (AS51167)
- Geolocation: Nuremberg, Germany (BY region)
- Network Role: CloudCompute hosting instance (no open ports, no services detected)
---
**2. Ownership & Infrastructure**
- Registered To: Johannes Selg (Contabo GmbH)
- ASN: AS51167
- Hosting Type: CloudCompute (firewalled, no public services)
- DNS: Resolves to `vmi377995.contaboserver.net` (Contabo hostname)
---
**3. Threat Indicators**
- No Active Threats: No malware indicators, spam, or known attacker associations.
- DNSBL Listings: 4 out of 8 DNSBL lists (potential abuse risk, though not confirmed).
- BGP Stability: Unstable route (likely due to cloud provider dynamics).
---
**4. Observation History**
- Recent Activity:
- Geolocation inferred via multi-signal inference (Germany, Nuremberg).
- No persistent malicious behavior detected (0 threat observations).
- DNSSEC validated, but DNSBL listings suggest potential misuse.
---
**5. Relationships & Network**
- Linked Entities:
- DNS: `vmi377995.contaboserver.net` (Contabo hostname).
- Network: Contabo subnet (`173.212.224.0/19`).
- Subnet Abuse Density: 0% (clean subnet).
---
**6. Recommendations**
- Monitor: Track DNSBL listings and BGP stability for potential abuse.
- Firewall: Block outbound traffic to this IP unless explicitly required.
- Verify: Confirm if the Contabo instance is authorized; consider contacting Contabo for clarification.
---
Conclusion: The IP is a legitimate cloud-hosted server with no current malicious activity. However, its high risk score and DNSBL associations warrant continued monitoring for anomalous behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 173.212.224.0/19 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi377995.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi377995.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 25, 3389, 8080 (4 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
๐ TLS Certificate
| SANs | vmi377995.contaboserver.net |
| Valid From | 2026-05-22T06:03:42+00:00 |
| Valid Until | 2026-08-20T06:03:41+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 05A3F44E13EA1F9CABEDDE694EA6810C3F78 |
| Thumbprint | 82978817CE5373BA4267388D0FA8A74A734D9AC6 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 18% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 26% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-27 07:16:58 UTC |
| Last Seen | 2026-06-29 03:55:08 UTC |
| Profile Built | 2026-06-29 15:57:02 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.