# IP Intelligence Briefing: 207.180.204.120
Classification: LOW RISK | Report Date: Current | Threat Level: Minimal
## Executive Summary
IP address 207.180.204.120 presents a low-risk profile with a risk score of 25. The address is classified as a cloud compute host operated by Contabo (ASN 51167) and resolves to the domain aguibou.be. No active threat campaigns, known attacker indicators, or spam source signatures were detected. The IP maintains stable ownership and shows no signs of persistent malicious activity.
## Infrastructure Profile
- Organization: Johannes Selg / CONTABO
- ASN: 51167
- CIDR Block: 207.180.192.0/19
- RIR: ARIN
- Infrastructure Type: Cloud Compute / Single-Service Host
- Service Purpose: Email/Hosting
## Geolocation Data
- Country: Germany (DE)
- Region: Grand Est
- City: Lauterbourg
- Coordinates: 51.17°N, 10.45°E
- Timezone: Europe/Berlin
- GeoValidation: Plausible (401.9km from claimed location, 5 probe count, average RTT 110.6ms)
## Network Services & Port Analysis
- Open Ports: TCP/22 (SSH)
- SSH Banner: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
- TLS Certificate: None detected
- HTTP Title: None detected
- Email Authentication: SPF and DMARC records present
## DNS Intelligence
- PTR Hostnames: mail.aguibou.be
- Domain: aguibou.be
- Forward Resolution: Confirmed (1 hostname)
- DNSBL Listings: 1 of 8 total lists flagged
## Threat Indicators Assessment
| Indicator | Status |
|---|---|
| Known Attacker | Negative |
| Tor Exit Node | Negative |
| Spam Source | Negative |
| Blacklist Count | 0 |
| Known Campaigns | None |
| Threat Feeds | None |
## Network Neighborhood Analysis
- Subnet: 207.180.204.120/24
- Abuse Density: 0%
- Classification: Clean
- Total Siblings: 1
- Threat Siblings: 0
- High/Medium Risk IPs: 0
## Relationship Graph
The IP maintains associations with:
- DNS Targets: mail.aguibou.be (multiple relationship entries)
- Network: CONTABO (multiple relationship entries)
- Total Relationships: 11
## Historical Observations
A total of 22 observations recorded since initial analysis:
- Latest (2026-06-21): Subnet classification "clean," abuse density 0%
- 2026-06-16: No banners detected, campaign likelihood "none"
- 2026-06-16: SSH service detected, ports scanned
- 2026-06-16: Geolocation validated as plausible
- 2026-06-16: Ownership stable (0 changes), no persistent malicious behavior detected
## Control Plane Intelligence
- Origin ASN: 51167
- BGP Prefix: 207.180.204.0/23
- Route Stability: False
- RPKI State: Not applicable
- IRR Consistency: Not applicable
- Operator Score: 0.2609 (Basic)
## Risk Assessment
Overall Risk Score: 25/100 (LOW)
The IP demonstrates characteristics consistent with legitimate cloud hosting infrastructure. The absence of threat indicators, combined with clean neighborhood classification and stable ownership, supports a low-risk classification. The single DNSBL listing suggests minor reputation concerns that do not correlate with active malicious campaigns.
## Recommended Actions
No specific firewall rules or mitigation actions are recommended at this time. The IP does not meet the threshold for automated blocking based on current threat intelligence.
Monitoring Recommendation: Continue passive monitoring. No immediate action required.
---
*Report generated using IPDebrief intelligence platform. All data sourced from live intelligence feeds and historical observation records.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 207.180.192.0/19 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | mail.aguibou.be |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | mail.aguibou.be |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 21% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 28% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-07 19:58:58 UTC |
| Last Seen | 2026-06-21 14:11:37 UTC |
| Profile Built | 2026-06-21 14:14:02 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.