IP INTELLIGENCE BRIEFING
IP Address: 173.249.10.164/32
Date: Current Analysis
Classification: Low Risk - Cloud Infrastructure
---
EXECUTIVE SUMMARY
IP 173.249.10.164 is a low-risk cloud computing address associated with Contabo infrastructure in Nuremberg, Germany. Risk score of 25 indicates minimal threat activity. No malicious indicators, blacklist listings, or campaign associations detected. The IP operates standard web services with no anomalous behavior observed.
NETWORK ATTRIBUTES
- Provider: Contabo (ASN: 51167)
- Infrastructure Type: Cloud Compute / Virtual Machine
- Location: Nuremberg, Germany (51.17°N, 10.45°E)
- Subnet: 173.249.10.0/23 (BGP prefix)
- Ownership Stability: Stable (no ownership changes recorded)
OPEN SERVICES
- Port 80/TCP: HTTP (Apache server banner)
- Port 443/TCP: HTTPS (Let's Encrypt TLS certificate)
- Port 22/TCP: SSH (OpenSSH 8.2p1)
TLS/SSL CERTIFICATE ANALYSIS
- Issuer: Let's Encrypt (R10)
- Subject: www.daktarionline.co.ke
- Associated Domains: cpanel.daktarionline.co.ke, cpcalendars.daktarionline.co.ke, cpcontacts.daktarionline.co.ke, daktarionline.co.ke, haron.dev, and 5 additional domains
- Certificate Status: Valid, not self-signed
THREAT INTELLIGENCE
- Threat Indicators: None detected
- Blacklist Status: Listed on 1 of 8 DNSBLs (low significance)
- Known Attacks: No confirmed attacks
- Campaign Associations: None
- Tor Exit Node: No
- Proxy/VPN: No
NETWORK NEIGHBORHOOD
- Subnet Risk Classification: Clean
- Abuse Density: 0%
- Threat Siblings in /24: 0
- Overall Risk Distribution: No high or medium risk neighbors
OBSERVATION HISTORY (22 Records)
- Monitoring Period: Consistent observations through June 20, 2026
- Provider Consistency: Contabo (stable)
- Geolocation: Consistent DE registration
- Infrastructure Type: Cloud (consistent)
- Notable Signals: DMARC policy configured (p=none for brevo.com)
ENTITY RELATIONSHIPS
- DNS Resolutions: vm3242360.contaboserver.net
- Network Associations: CONTABO infrastructure
- Related Entities: 53 total relationships (primarily network and DNS associations)
RECOMMENDED ACTIONS
- Firewall Rules: Not required (risk score 25, low threat)
- Monitoring: Standard logging recommended for SSH (port 22) exposure
- Action Priority: Low
- Note: Standard cloud infrastructure; no immediate blocking recommended
SOC ANALYST NOTES
This IP represents typical cloud hosting infrastructure. The combination of web services, SSH access, and legitimate SSL certificates for a Kenyan domain suggests legitimate business hosting. However, the SSH service exposure warrants standard monitoring for brute force attempts. The single DNSBL listing appears incidental with minimal operational impact. No active threat indicators present.
CONFIDENCE: High (based on 22 historical observations and stable network classification)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3242360.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3401454.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 0/3 domains |
| DMARC | 1/3 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 3 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 34% | 2 | 4 |
| ownership | 20% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 18:40:14 UTC |
| Last Seen | 2026-06-29 00:25:14 UTC |
| Profile Built | 2026-06-29 06:28:33 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.