# IP Intelligence Briefing: 173.249.42.54/32
## Executive Summary
IP address 173.249.42.54 presents a low-risk threat profile (Risk Score: 25) associated with CONTABO cloud infrastructure. The IP operates as a web hosting server with standard HTTP/HTTPS services and SSH access. No active malicious indicators or threat campaigns were identified during analysis.
## Profile Assessment
Ownership & Infrastructure:
- ASN: 51167 (CONTABO)
- Organization: Johannes Selg
- Network: 173.249.32.0/19
- Classification: CloudCompute infrastructure
- Status: Cloud-hosted web server
Geolocation:
- Consensus Location: Germany (DE)
- Coordinates: 51.17°N, 10.45°E
- Timezone: Europe/Berlin
- GeoValidation: Plausible (ICMP validation blocked)
Network Services:
- Port 80/TCP: HTTP (Apache/2.4.58)
- Port 443/TCP: HTTPS (TLS certificate: CN=app.pageme.ai, Let's Encrypt)
- Port 22/TCP: SSH (OpenSSH_9.6p1 Ubuntu)
- HTTP Status: 403 Forbidden
DNS Resolution:
- PTR Hostname: vmi3292846.contaboserver.net
- Forward Resolution: Forward confirmed
- Email Authentication: SPF and DMARC configured
Threat Indicators:
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: None
## Observation History (24 Signals)
Recent signal activity (2026-08-05) indicates:
- Geographic signals show mixed attribution (DE consensus with FR signals)
- HTTP responses consistently return 403 status codes
- TLS certificate validation issues observed
- No emerging malicious behavior patterns detected
## Relationship Network
The IP maintains DNS associations with vmi3292846.contaboserver.net and same-network relationships within CONTABO infrastructure. No external organization or certificate associations beyond the hosting provider were identified.
## Neighborhood Analysis
Subnet: 173.249.42.0/24
- Abuse Density: 0 (Clean classification)
- Active Neighbors: 1 (173.249.42.94, Risk Score: 25)
- Risk Distribution: 1 Low, 0 Medium, 0 High
- Overall Assessment: No inherited subnet abuse risk
## SOC Recommendations
Actionable Firewall Rules:
```bash
# Allow legitimate web traffic (consider rate limiting)
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j ACCEPT
# SSH access - restrict to known IPs if possible
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
# Block if misconfiguration observed
iptables -A INPUT -p tcp --dport 80 -m state --state NEW -j DROP
```
Monitoring Priorities:
- Monitor for changes in DNSBL listing status
- Track HTTP 403 response patterns
- Watch for TLS certificate expiration (Let's Encrypt)
- Monitor for new service port openings
Threat Level: LOW
Recommendation: No immediate blocking required. Standard monitoring protocols apply. The IP operates within legitimate cloud infrastructure with no active threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 173.249.32.0/19 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3292846.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3292846.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Apache/2.4.58 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | app.pageme.ai |
| Valid From | 2026-07-11T16:11:39+00:00 |
| Valid Until | 2026-10-09T16:11:38+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 05C61D78A5B5C24CB8F8E50FF60A91257A4C |
| Thumbprint | 7944645C12578E9F26185EEC2EE65DC3914B5B93 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 35% | 2 | 4 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 01:11:18 UTC |
| Last Seen | 2026-08-12 16:33:23 UTC |
| Profile Built | 2026-08-12 16:48:49 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 28 |
Full dossier details are available via our API.