IPDebrief

176.95.238.208

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 176.95.238.208

Date: 2026-06-02

---

**1. Core Profile**

- Reputation: Low Risk (riskScore: 0, providerScore: 0, authorityScore: 0).

- Threat Indicators: No malicious activity, spam, or known attacker associations.

- Network Role: Mobile carrier infrastructure (Vodafone Germany IP Core Backbone), LTE/5G network.

- Location: Würzburg, Bavaria, Germany (latitude: 51.17, longitude: 10.45).

- ISP: Vodafone GmbH (MCC: 262, MNC: 02).

- Accuracy: 400 km radius, RTT consistency (avg: 120.6 ms).

- ASN: 3209 (Vodafone Germany).

- Subnet: 176.95.238.208/24, classified as "mostly_clean" with abuse density 1.

---

**2. Network & Service Activity**

- Open ports: HTTP (80), HTTPS (443).

- TLS Certificate:

- Issuer: Let’s Encrypt (CN=R10).

- Subject: chefportrait.de (SAN: chefportrait.de).

- Valid: No expiration date provided (may require further validation).

- PTR hostname: *business-176-095-238-208.static.arcor-ip.net*.

- No email authentication records (SPF/DMARC).

- BGP prefix: 176.95.0.0/16.

- RPKI state: Not reported.

- DNSSEC: Validated.

---

**3. Observation History**

- 23 signals recorded (last 30 days).

- No persistent malicious activity; threat observation count: 1.

- Geolocation and network stability consistent over time.

- One "connection_failed" signal for HTTPS (confidence: 30%).

- No DNSBL listings or route instability.

---

**4. Relationships & Neighborhood**

- DNS: *business-176-095-238-208.static.arcor-ip.net*.

- Network: DE-ARCOR-20110711 (Vodafone).

- /24 Subnet: 176.95.238.208/24.

- Neighbors: 0 active IPs listed (abuse density: 0).

- Classification: "mostly_clean" with inherited risk score: 2.

---

**5. Threat & Actionable Insights**

- No malware, phishing, or campaign activity detected.

- TLS certificate appears legitimate but tied to a specific domain (*chefportrait.de*).

- Monitor traffic to *chefportrait.de* for unusual patterns.

- No immediate firewall rules required due to low risk.

- Validate TLS certificate expiration date for *chefportrait.de*.

---

Conclusion:

This IP is a legitimate mobile carrier asset associated with Vodafone Germany. It serves a business domain (*chefportrait.de*) via HTTPS and shows no malicious activity. No further action is required, but ongoing monitoring of the associated domain is advised.

Product: IPDebrief | Copyright: © 2026 Jason Alberino. All rights reserved.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡©πŸ‡ͺ Germany
RegionBavaria
CityWürzburg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

🏒 Ownership & Registration

OrganizationVodafone Germany IP Core Backbone
ASNAS3209
Network Nameβ€”
CIDR Blockβ€”
RIRRIPE
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRbusiness-176-095-238-208.static.arcor-ip.net
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesbusiness-176-095-238-208.static.arcor-ip.net

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPF1/2 domains
DMARC0/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureMobile
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
Mobile

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

An expired certificate for CN=chefportrait.de was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
πŸ”’
CN=chefportrait.de
Issued by CN=R10, O=Let's Encrypt, C=US
Self-signed: No
SANschefportrait.de
Valid From2024-12-07T16:56:06+00:00
Valid Until2025-03-07T16:56:05+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number036668B4F3EC368FCF05D36D33531F55AD3E
Thumbprint760AC0F339CEF7E37DF53B076417093589AD563B

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
13%
11
services
26%
23
ownership
24%
23
reputation
24%
13
geolocation
30%
23
Overall24%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:03:56 UTC
Last Seen2026-06-22 22:04:21 UTC
Profile Built2026-06-22 22:09:33 UTC
Data FreshnessLive
Signal Types24
Total Observations26
πŸ” 24 signal types Β· 26 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.