IPDebrief

194.233.86.63

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# Intelligence Briefing: IP 194.233.86.63

Classification: LOW RISK

Date: 2026-07-31

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP address 194.233.86.63 is a low-risk web server hosted on a Contabo infrastructure in Singapore. The IP carries a risk score of 30/100, is associated with a virtual machine instance (vmi2784751.contaboserver.net), and shows no indicators of active malicious activity. No immediate defensive actions are recommended, though monitoring of open ports and TLS configuration is advised.

---

## Ownership and Infrastructure

---

## Geolocation

---

## DNS and Hostname Resolution

---

## Network Services and Exposure

Open Ports:

PortProtocolService
80TCPHTTP
443TCPHTTPS
22TCPSSH (OpenSSH 9.6p1)
8443TCPHTTPS-Alt

TLS Configuration:

Note: SSH access is publicly exposed, which is a potential attack vector.

---

## Threat Indicators

---

## Neighborhood Analysis (/24 Subnet)

Subnet: 194.233.86.0/24

Abuse Density: 0 (Clean)

Total Siblings: 4

Active Siblings: 1

Threat Siblings: 0

Neighbor Risk Scores:

IP AddressRisk ScoreAuthority Score
194.233.86.63300
194.233.86.1432560
194.233.86.223060
194.233.86.2455060

---

## Historical Observations

Observation Period: 2026-07-31

Total Observations: 20 signals

Temporal Trends:

Recent Signals Include:

Trend Assessment: IP shows no escalation in threat activity. Stable ownership with no recent malicious behavior.

---

## Relationships

Primary Association: vmi2784751.contaboserver.net (DNS)

Network Association: CONTABO-ASIA-20210409-06 (Same Network)

Multiple DNS and network relationship links indicate this IP is part of a larger virtualized infrastructure environment. No external organizational or certificate-based relationships detected.

---

## Risk Assessment

Overall Risk: LOW (30/100)

Stability: N/A

Control Plane Risk: Low (Basic operator score: 0.2609)

Key Risk Factors:

1. Open SSH port (22) - potential lateral movement target

2. Self-signed TLS certificate - indicates unverified hosting

3. No SPF/DMARC records - email authentication gaps

4. Single DNSBL listing - potential minor reputation concern

Mitigating Factors:

1. No active threat indicators

2. Clean neighborhood classification

3. No known campaign associations

4. Stable ownership history

---

## Recommendations for SOC Analysts

1. Monitor SSH Access: Track connection attempts to port 22 for brute force activity

2. Certificate Validation: Review self-signed certificate for potential spoofing

3. Email Authentication: Verify if this IP should be blocked from sending email (no SPF/DMARC)

4. Baseline Behavior: Establish normal traffic patterns for this infrastructure

5. Neighborhood Monitoring: Keep awareness of subnet 194.233.86.0/24; one neighbor (194.233.86.245) has elevated risk (50/100)

---

## Conclusion

IP 194.233.86.63 is a standard web hosting endpoint with low risk characteristics. The infrastructure is associated with legitimate Contabo hosting in Singapore. While no immediate threat exists, the exposed SSH service and self-signed certificate warrant standard monitoring. No blocking or restrictive firewall rules are recommended at this time.

Status: Continue Monitoring

Next Review: 30 days or upon threat signal detection

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
Regionβ€”
CitySingapore
TimezoneAsia/Singapore
Latitude1.35
Longitude103.82

🏒 Ownership & Registration

OrganizationIRT-CAPL-SG
ASNAS141995
Network NameCONTABO-ASIA-20210409-06
CIDR Block194.233.84.0/22
RIRRIPE
CountrySG
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRvmi2784751.contaboserver.net
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesvmi2784751.contaboserver.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
8443https-alttcpβ€”
Closed Ports25, 3389, 8080 (4 open / 7 scanned)
Servernginx
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.13

πŸ” TLS Certificate

An expired certificate for CN=cloudpanel.clp was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
⚠️
CN=cloudpanel.clp
Issued by CN=cloudpanel.clp
Self-signed: Yes
SANscloudpanel.clpwww.cloudpanel.clp
Valid From2019-10-14T13:34:38+00:00
Valid Until2020-10-13T13:34:38+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period365 days
Serial Number00
Thumbprint3BECE07FF14C8422E15E2D725E47F72289009311

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
25%
11
Overall16%44
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-30 11:03:39 UTC
Last Seen2026-08-01 04:25:30 UTC
Profile Built2026-07-31 02:17:21 UTC
Data FreshnessLive
Signal Types22
Total Observations22
πŸ” 22 signal types Β· 22 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.