# Threat Intelligence Briefing: 195.26.244.42/32
## Executive Summary
IP 195.26.244.42 is a low-risk (score: 25) cloud-hosted infrastructure address operating within Contabo's German network. The IP presents as a standard web server virtual machine with no active threat indicators, though geolocation validation inconsistencies warrant monitoring.
## Ownership & Infrastructure
- Provider: Contabo (cloud hosting)
- ASN: AS40021 (Johannes Selg)
- CIDR Block: 195.26.240.0/21
- Network Name: TT-20240430
- RIR: RIPE
- Infrastructure Type: Cloud Compute / Web Server
## Technical Profile
- DNS: vmi2356336.contaboserver.net (virtual machine identifier, no hosted domains)
- Open Ports: 22 (SSH), 80 (HTTP), 443 (HTTPS)
- TLS Certificate: CN=Easypanel (organizational certificate)
- HTTP/2: Enabled
- Security Headers: None configured (no HSTS, CSP, or referrer policy)
## Geolocation Validation
- Reported Location: Germany (51.17°N, 10.45°E)
- RTT Anomaly: 39ms observed vs 142.3ms minimum possible for 7,115km distance
- Status: GeoPlausible: false (distance/RTT mismatch indicates potential routing anomaly or false geo claim)
- Historical Variations: Claims detected in GB, US, and DE across observation period
## Threat Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence: Not elevated
- Blacklist Status: 0 pulsedive listings, 0 DNSBL lists
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
## Neighborhood Analysis
- Subnet: 195.26.244.0/24
- Abuse Density: 0.5 (classified: mostly_clean)
- Sibling IPs: 1 additional IP (195.26.244.64, risk score: 25)
- Threat Siblings: 1
## Security Actions & Recommendations
No automated firewall rules recommended at this risk level. Monitor for:
1. RTT/Geolocation discrepancies - Indicates potential IP spoofing or routing manipulation
2. Port 22 exposure - Standard SSH access; verify if legitimate
3. Historical blacklist activity - 8 listings detected with 1 "high" severity listing in observation history
## Historical Observations
24 total observations recorded. Recent activity (2026-08-05) shows:
- Geolocation validation failures with multiple country claims
- Blacklist listing activity with high-severity classification
- Consistent web server fingerprinting (HTTP/2, status 200)
---
Classification: LOW RISK - Cloud Infrastructure
Action: Monitor geolocation inconsistencies; no immediate blocking required.
Report Generated: Based on IPDebrief intelligence platform data
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS40021 |
| Network Name | TT-20240430 |
| CIDR Block | 195.26.240.0/21 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi2356336.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi2356336.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.11 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2025-04-02T13:19:12+00:00 |
| Valid Until | 2035-03-31T13:19:12+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
| Serial Number | 49451347CA5D1FFF55A2E4A6D2A2F45363071123 |
| Thumbprint | 327F93E6E9DD9FF8FA7CB0402DA50960A8CE1822 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 32% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:55:12 UTC |
| Last Seen | 2026-08-12 15:52:19 UTC |
| Profile Built | 2026-08-12 16:06:30 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 28 |
Full dossier details are available via our API.