# IP INTELLIGENCE BRIEFING
Target: 173.212.236.96/32
Classification: Cloud Compute Infrastructure
Report Date: Current
Status: Low Risk
---
## EXECUTIVE SUMMARY
IP 173.212.236.96 is a low-risk cloud computing endpoint hosted by Contabo (AS51167) in Lauterbourg, Grand Est, Germany. The address operates as a multi-service virtual machine with minimal threat indicators. Current risk assessment scores 25/100 with no active malicious campaigns correlated.
---
## INFRASTRUCTURE PROFILE
Ownership & Provider:
- ASN: 51167 (Johannes Selg / Contabo)
- Network: 173.212.224.0/20
- Registration: ARIN
- Infrastructure Type: Cloud Compute / Hosting
Geolocation:
- Country: Germany (DE)
- Region: Grand Est
- City: Lauterbourg
- Coordinates: 51.17°N, 10.45°E
Network Services:
- Port 80/TCP: HTTP (Apache/2.4.58 Ubuntu)
- Port 22/TCP: SSH (OpenSSH_9.6p1)
- Server Fingerprint: Apache/2.4.58 on Ubuntu
DNS Resolution:
- PTR: vmi3049186.contaboserver.net
- Forward Resolution: vmi3342671.contaboserver.net
- Hosted Domain: contaboserver.net
---
## THREAT ASSESSMENT
Risk Score: 25 (Low Risk)
Threat Indicators:
- DNSBL Listed: 1 of 8 lists
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not available
Control Plane:
- Route Stability: False
- BGP Origin: 173.212.224.0/20
- RPKI State: Not validated
- DNSSEC: Valid
---
## OBSERVATION HISTORY
Analysis of 25 historical observations reveals stable operational patterns:
Temporal Trends:
- Most recent signals: 2026-06-25
- Historical operator scores: 0.1304 to 0.2609
- No significant risk escalation detected
- Threat persistence: 0 days
- Ownership changes: 0
Signal Quality:
- Signal type 15 (comprehensive): 6 dimensions covered
- Signal type 2349 (operator): Basic to Minimal classification
- Overall confidence: Low-to-moderate (0.23โ0.80)
---
## NETWORK RELATIONSHIPS
Relationship Graph: 63 total relationships identified
Key Associations:
- Network: Multiple CONTABO network relationships
- DNS Hostnames: vmi3049186.contaboserver.net (primary)
- Infrastructure: Virtual machine identifiers (vmi3xxx pattern)
Relationship Type Distribution:
- Same Network: Primary association
- DNS Association: Hostname mappings
---
## NEIGHBORHOOD ANALYSIS
Subnet: 173.212.236.96/24
Abuse Metrics:
- Abuse Density: 1
- Classification: Mostly Clean
- Active Siblings: 1
- Threat Siblings: 1
Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 1
The /24 subnet demonstrates minimal abuse activity with predominantly clean classifications.
---
## RECOMMENDED ACTIONS
Firewall Rules:
- No blocking recommended for current risk profile
- Standard egress filtering applicable
- Consider rate limiting on port 22 if internal exposure
Monitoring Priority:
- Monitor for changes in DNS associations
- Track Contabo network-wide abuse trends
- Watch for escalation in DNSBL listings
Threat Hunting:
- No immediate threat indicators warrant active hunting
- Standard logging and monitoring sufficient
- Review if IP appears in campaign correlation data
---
## ANALYST NOTES
The IP represents typical cloud hosting infrastructure with no evidence of malicious activity. The single DNSBL listing and low-risk classification suggest historical benign traffic or transient scanning activity. The Contabo hosting environment is widely used for legitimate applications. Recommend continued passive monitoring without additional mitigations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3049186.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3342671.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache/2.4.58 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 28% | 2 | 4 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 24% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:33:40 UTC |
| Last Seen | 2026-06-27 15:24:14 UTC |
| Profile Built | 2026-06-28 09:30:13 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.