IPDebrief

185.252.232.218

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 185.252.232.218

*Generated via IPDebrief Threat Intelligence Platform*

---

**Core Risk Profile**

- Identified as a Tor exit node (high-risk association).

- Observed in 1 DNS resolution (`vmi1347637.contaboserver.net`).

- Provider: Tor Exit Node (IPv4 /24 subnet).

- Geolocation: Germany (Lauterbourg, 51.17°N, 10.45°E).

- ASN: 51167 (Johannes Selg).

---

**Threat Observations**

- Consistent "Moderate" risk classification across 54 observations (last 30 days).

- No spikes in malicious activity detected.

- SSH service active (port 22, OpenSSH 8.4).

- Tor exit nodes are often used for covert communication or as entry points for attacks.

---

**Network Relationships**

- Linked to `vmi1347637.contaboserver.net` (no abuse indicators).

- 185.252.232.0/24 subnet: 3 total IPs, 2 active.

- Risk Distribution: 0 high-risk, 0 medium-risk, 2 low-risk IPs.

---

**Actionable Insights**

1. Monitor Tor Exit Traffic:

- Block or closely inspect traffic originating from or passing through this IP, as Tor exit nodes are frequently associated with illicit activities.

2. Investigate Hostname:

- Validate the reputation of `vmi1347637.contaboserver.net` for potential hosting provider ties or abuse.

3. Subnet Analysis:

- The subnet has low abuse density, but the IP’s Tor association warrants closer scrutiny.

---

Recommendation:

*Generated on 2026-06-15 | Data sourced from IPDebrief intelligence feeds.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡©πŸ‡ͺ Germany
RegionGrand Est
CityLauterbourg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

🏒 Ownership & Registration

OrganizationJohannes Selg
ASNAS51167
Network Nameβ€”
CIDR Block185.252.232.0/24
RIRRIPE
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRvmi1347637.contaboserver.net
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesvmi1347637.contaboserver.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u3

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
20%
23
services
12%
22
ownership
22%
34
reputation
28%
13
geolocation
27%
23
Overall23%1219
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-22 13:35:41 UTC
Last Seen2026-06-28 19:23:18 UTC
Profile Built2026-06-29 07:26:26 UTC
Data FreshnessLive
Signal Types28
Total Observations52
πŸ” 28 signal types Β· 52 observations collected
This report is generated from 28+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.