IPDebrief

185.187.235.179

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IPDEBRIEF INTELLIGENCE BRIEFING

Target: 185.187.235.179

Classification: Cloud Hosting Infrastructure (Low Risk)

Risk Score: 25/100

OVERVIEW

The IP address 185.187.235.179 operates on Contabo cloud infrastructure (ASN 40021) with a low-risk reputation score of 25. The asset is registered to organization Johannes Selg and resolves to hostname vmi1365041.contaboserver.net. Geolocation data indicates deployment in Germany (DE) with geographic validation discrepancies noted.

INFRASTRUCTURE PROFILE

Network classification identifies the IP as cloud hosting infrastructure with active web server services. Open ports include HTTP (80), HTTPS (443), and SSH (22). TLS certificates issued by Let's Encrypt cover multiple domains including tags.mgcounts.com, api.lcedit.com, api.terra.photos, and app.terra.photos. The reverse DNS resolves to vmi1365041.contaboserver.net with forward resolution confirmed. The server banner indicates nginx/1.18.0 running on Ubuntu.

THREAT ASSESSMENT

Current threat indicators show no active malicious campaigns, known attacker attribution, or spam source designation. Blacklist count registers at zero. Control plane analysis reveals 1 DNSBL listing across 8 total lists with an operator score of 0.2609. The IP is not classified as a Tor exit node, proxy, CDN, or VPN service. No evidence of persistent malicious behavior observed in historical records.

HISTORICAL OBSERVATIONS

Signal observation history contains 29 recorded events. Recent DNS activity shows associations with domains mgcounts.com, terra.photos, lcedit.com, and contaboserver.net. Listing signals detected with varying confidence levels across 8 blacklist sources. No escalation in threat posture identified over the observation period.

NETWORK RELATIONSHIPS

The IP maintains 50 relationships including DNS associations to vmi1365041.contaboserver.net and network associations to subnet TT-20221020. The /24 subnet (185.187.235.0/24) shows abuse density of 1 with classification marked as mostly_clean. One active sibling IP and one threat sibling IP identified within the subnet boundary.

RECOMMENDED ACTIONS

No immediate firewall rules or blocking actions recommended at this time. The low-risk profile combined with absence of active threat indicators supports continued monitoring rather than blocking. However, analysts should monitor the associated domains (tags.mgcounts.com, api.lcedit.com, api.terra.photos, app.terra.photos) for anomalous activity patterns.

SOC INTELLIGENCE SUMMARY

185.187.235.179 presents as a standard Contabo cloud hosting IP with legitimate web server operations. No active threat indicators support immediate remediation. Recommend inclusion in threat feed monitoring for associated domains and observation of subnet-level activity for any abuse density changes.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionMissouri
CitySt Louis
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationJohannes Selg
ASNAS40021
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvmi1365041.contaboserver.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvmi1365041.contaboserver.net

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPF0/4 domains
DMARC1/4 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked4 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.18.0 (Ubuntu)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.12

๐Ÿ” TLS Certificate

An expired certificate for CN=tags.mgcounts.com was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
๐Ÿ”’
CN=tags.mgcounts.com
Issued by CN=R12, O=Let's Encrypt, C=US
Self-signed: No
SANsapi.lcedit.comapi.terra.photosapp.terra.photostags.mgcounts.com
Valid From2026-02-14T04:26:11+00:00
Valid Until2026-05-15T04:26:10+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number06D2DC7BCDD898858717AF43BE6B016283B7
Thumbprint1AC2F1AD577D0E18106E79ADB72250E4E6AAD7EC

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
8%
11
services
26%
23
ownership
24%
23
reputation
26%
13
geolocation
33%
23
Overall24%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-13 12:12:23 UTC
Last Seen2026-06-27 23:09:11 UTC
Profile Built2026-06-28 17:14:11 UTC
Data FreshnessLive
Signal Types24
Total Observations31
๐Ÿ” 24 signal types ยท 31 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.