# IP Intelligence Briefing: 207.180.229.239
## Executive Summary
IP 207.180.229.239 presents a moderate risk profile (score: 50) associated with Contabo cloud infrastructure. The address is part of a low-abuse-density subnet with minimal threat indicators.
## Infrastructure Profile
- Organization: Contabo GmbH (AS51167)
- Infrastructure Type: CloudCompute/Hosting
- Geolocation: Lauterbourg, Grand Est, France (51.17°N, 10.45°E)
- Network Classification: Cloud infrastructure with firewalled/no services exposed
- DNS Resolution: vmi3237984.contaboserver.net / vmi3334910.contaboserver.net (Virtual Machine instances)
## Threat Assessment
- Risk Score: 50 (Moderate Risk)
- Known Threats: None detected in threat feeds
- Blacklist Status: 0 direct blacklist matches; 2 DNSBL entries across 8 total lists
- Proxy/VPN Indicators: Historical proxy detection observed (Confidence: 0.85)
- Tor Exit Node: No
## Observational History
Analysis of 21 signal observations reveals:
- Recent observations (June 2026) show varying confidence levels (0.22โ0.60)
- Geo validation inconclusive: One signal flagged location as implausible, others accepted
- One observation identified risk score of 66 with proxy/VPN classification
- Most recent probe (June 19): ICMP validation blocked
- Threat persistence: 0 days; not persistently malicious
## Network Neighborhood
- Subnet: 207.180.229.0/24
- Abuse Density: 1 (Low)
- Classification: mostly_clean
- Threat Siblings: 1
- Active Siblings: 0
## Related Entities
- DNS Associations: Multiple Contabo VMI hostname mappings
- Network Association: CONTABO network infrastructure
- Relationship Count: 36 total relationships (primarily DNS and network-level)
## Recommended Actions
Based on risk profile, the following defensive measures are recommended:
Firewall Rules:
- `iptables -A INPUT -s 207.180.229.239 -j DROP`
- `nft add rule inet filter input ip saddr 207.180.229.239 drop`
- `nginx: deny 207.180.229.239;`
WAF Configuration:
- Cloudflare WAF: Block IP with expression `ip.src eq 207.180.229.239`
- AWS WAF: Block addresses `207.180.229.239/32`
## Assessment Notes
The IP is associated with Contabo's virtual infrastructure, which commonly hosts VMI instances. No active exploitation campaigns or known attacker indicators were detected. The moderate risk score reflects historical proxy/VPN classification and DNSBL listings. Given the cloud hosting context and lack of active threat indicators, this address may be monitored rather than aggressively blocked, depending on organizational threat tolerance.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | 207.180.228.0/23 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3237984.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3334910.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 33% | 2 | 3 |
| services | 26% | 2 | 3 |
| ownership | 37% | 3 | 5 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 33% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:10 UTC |
| Last Seen | 2026-06-27 04:05:07 UTC |
| Profile Built | 2026-06-27 22:12:04 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 32 |
Full dossier details are available via our API.