IP Intelligence Briefing: 178.238.226.181
Date: 2026-06-08
---
**1. Core Profile**
- Risk Score: Low (25/100) | Provider Score: 0 | Authority Score: 0
- Ownership: Registered to Johannes Selg (AS: 51167, RIPE) | Abuse contact available via RDAP.
- Geolocation: Germany (DE), Grand Est region, Lauterbourg. Coordinates: 51.17°N, 10.45°E.
- Network Role: Cloud compute instance (Contabo) | Hosting provider | No public services detected.
- Threat Indicators: Clean | No malicious activity, spam, or known attacker associations.
---
**2. Observation History**
- Recent Activity:
- DNS resolution for `vmi3257818.contaboserver.net` confirmed (June 8, 2026).
- Subnet analysis (178.238.226.0/23) shows abuse density: 1 (low risk).
- No persistent malicious behavior or threat persistence observed.
---
**3. Relationships**
- Linked Entities:
- Contabo (cloud hosting provider).
- DNS Hostname: `vmi3257818.contaboserver.net` (no further subdomains or domains).
- Network: Subnet 178.238.226.0/23, shared with other Contabo instances.
---
**4. Neighborhood Analysis**
- Subnet: 178.238.226.181/24 | Abuse Density: 1 (mostly clean).
- Neighbors:
- 178.238.226.119: Risk score 0 (low risk).
- 178.238.226.170: No risk score available (possibly newly registered or private).
---
**5. Threat Assessment**
- No malicious indicators detected (no blacklists, spam, or campaigns).
- Subnet Risk: Low, but one neighbor (178.238.226.170) has unknown risk.
- Recommendation: Monitor for unexpected DNS changes or subnet activity. No immediate action required.
---
Summary:
The IP is a legitimate cloud compute instance owned by Johannes Selg, hosted on Contabo. No malicious activity detected. While the subnet has low abuse density, ongoing monitoring is advised due to one neighbor with unknown risk. No firewall rules or mitigation actions are recommended at this time.
Source: IPDebrief Threat Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3257818.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3337980.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 0/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | beautybell.milevag.comdemo.milevag.commilevag.comtodabellasalon.milevag.comwww.milevag.com |
| Valid From | 2026-06-13T17:32:39+00:00 |
| Valid Until | 2026-09-11T17:32:38+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 05678AF9B7A27FAF63A899ED368DC5C98FAA |
| Thumbprint | 88F9F1D60995CA836CB1D183FB0C410E7ABC4001 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 29% | 2 | 4 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-17 21:14:37 UTC |
| Last Seen | 2026-06-28 05:45:36 UTC |
| Profile Built | 2026-06-28 23:49:57 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.