IPDebrief

173.212.251.230

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 173.212.251.230/32

Classification: Moderate Risk (Score: 40/100) | Infrastructure: Web Server | Provider: CONTABO (Cloud Hosting)

---

## Executive Summary

IP address 173.212.251.230 is a moderate-risk cloud computing host operating under the CONTABO infrastructure (ASN 51167) located in Nuremberg, Germany. The asset functions as a web server with standard HTTP/HTTPS services. Risk scoring indicates moderate concern (40/100) primarily driven by DNSBL listings on 2 of 8 monitored blacklists. No active threat indicators, known campaigns, or exploit activity detected.

---

## Ownership & Infrastructure

AttributeDetails
**Organization**Johannes Selg (CONTABO)
**ASN**51167
**CIDR Block**173.212.224.0/19
**Geolocation**Nuremberg, Bavaria, Germany (DE)
**Infrastructure Type**Cloud Compute / Hosting
**Network Role**Web Server

Network Classification: Cloud-hosted infrastructure with hosting services enabled. The IP operates on nginx web server stack with HTTP/2 protocol support.

---

## Service & DNS Profile

Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS)

DNS Resolution: server01.techfol.hu

TLS Configuration:

HTTP Fingerprint:

---

## Threat Intelligence Assessment

Threat Indicators:

Campaign Correlation: None detected. No certificate matches or correlated IP activity observed.

Risk Breakdown:

---

## Observation History (24 Signals)

Recent signal observations (June 2026) show consistent infrastructure characteristics:

No significant signal degradation or escalation observed in the observation window.

---

## Network Neighborhood Analysis

Subnet: 173.212.251.230/24

The subnet exhibits minimal abuse density with low inherited risk, indicating the target IP operates in a generally clean network environment.

---

## Related Entities (27 Relationships)

Network Associations:

DNS Associations:

No organization or certificate relationships detected beyond the primary hosting infrastructure.

---

## Recommended Security Actions

Risk Score: 40/100 (Moderate)

Actionable Recommendations:

Firewall Rule Templates (if blocking required):

iptables:

```bash

iptables -A INPUT -s 173.212.251.230 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 173.212.251.230 drop

```

nginx:

```nginx

deny 173.212.251.230;

```

Cloudflare WAF:

```json

{

"action": "block",

"filter": {

"expression": "ip.src eq 173.212.251.230"

}

}

```

AWS WAF:

```json

{

"Addresses": ["173.212.251.230/32"],

"Description": "IPDebrief risk 40"

}

```

---

## Intelligence Narrative

IP 173.212.251.230 represents a standard cloud-hosted web server within the CONTABO infrastructure. The moderate risk score (40/100) reflects DNSBL presence without active exploitation indicators. The IP maintains consistent operational characteristics across observation periods with stable nginx web server configuration and valid TLS certificate. No evidence of malicious activity, command-and-control communication, or participation in known threat campaigns.

The subnet environment (173.212.251.230/24) shows low abuse density, suggesting the infrastructure operates within acceptable parameters for hosting services. DNSBL listings on 2 of 8 monitored blacklists warrant monitoring but do not indicate immediate threat.

Suggested SOC Action: Maintain standard monitoring with alert thresholds for any deviation from established HTTP/TLS baseline. No immediate blocking required unless additional threat indicators emerge.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionBY
CityNuremberg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationJohannes Selg
ASNAS51167
Network NameCONTABO
CIDR Block173.212.224.0/19
RIRARIN
CountryDE
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRserver01.techfol.hu
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesserver01.techfol.hu

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Servernginx
HTTP Titleโ€”

๐Ÿ” TLS Certificate

An expired certificate for CN=server01.techfol.hu was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
๐Ÿ”’
CN=server01.techfol.hu
Issued by CN=R12, O=Let's Encrypt, C=US
Self-signed: No
SANsserver01.techfol.hu
Valid From2025-09-11T10:51:43+00:00
Valid Until2025-12-10T10:51:42+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number06E53969AE07FB625DA6179BADB883861E32
ThumbprintA780F89EA0260C9589462DCD1072C0810C645937

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
24
routing
8%
11
services
30%
23
ownership
27%
23
reputation
26%
13
geolocation
34%
23
Overall25%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-25 00:40:42 UTC
Last Seen2026-06-29 00:52:53 UTC
Profile Built2026-06-29 06:56:25 UTC
Data FreshnessLive
Signal Types24
Total Observations26
๐Ÿ” 24 signal types ยท 26 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.