IP Intelligence Briefing: 178.18.242.84
Date: 2026-06-16
1. Core Profile
- Risk Score: Low (25/100) | Reputation: Clean | Provider: Tor Exit Node
- Geolocation: Paris, France (Grand Est region) | ASN: 51167 (Contabo GmbH)
- Network Role: Tor Exit Node | Services: No open ports detected
- Ownership: No registered ASN/org details | DNS: PTR hostname `vmi3185617.contaboserver.net`
2. Threat Indicators
- DNSBL Listing: 1 high-severity listing (confidence: 85%) | Malware Campaigns: None detected
- Email Security: No SPF/DMArC records for `contaboserver.net` | TLS/SSL: No certificate data
3. Observation History
- Recent Activity (30d): 13 signals observed, including:
- DNS resolution for `contaboserver.net` (no email security policies)
- BGP prefix `178.18.240.0/20` (Contabo GmbH)
- DNSSEC-valid reverse DNS (`84.242.18.178.in-addr.arpa`)
- Trend: No significant changes in risk profile over time.
4. Relationships
- DNS Association: Linked to `vmi3185617.contaboserver.net` (hosted domain: `contaboserver.net`)
- BGP: Part of `178.18.240.0/20` (Contabo GmbH, Germany)
5. Neighborhood Analysis
- Subnet: `178.18.242.84/24` | Abuse Density: 0%
- Neighbors: No active IPs in the subnet (0 siblings detected)
6. Recommendations
- Monitor: The DNSBL listing for `178.18.242.84` and verify if it aligns with known threats.
- Investigate: Contaboβs hosting infrastructure for potential vulnerabilities (e.g., misconfigured DNS/email security).
- Blocklist: Consider blocking the DNSBL listing if confirmed malicious.
- Network: Given the Tor exit node association, monitor for anomalous traffic patterns.
Conclusion:
The IP is associated with a hosting provider (Contabo) and shows no direct malicious activity. However, the DNSBL listing and lack of email security policies for the linked domain warrant further investigation. No immediate action is required, but continuous monitoring is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 178.18.240.0/21 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vmi3185617.contaboserver.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vmi3185617.contaboserver.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 40% | 3 | 6 |
| reputation | 26% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 29% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-09 20:15:40 UTC |
| Last Seen | 2026-06-26 21:06:52 UTC |
| Profile Built | 2026-06-27 17:36:16 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 57 |
Full dossier details are available via our API.