# INTELLIGENCE BRIEFING: 207.244.227.91
Date: Current
Analyst: IPDebrief Intelligence Unit
Subject: IP Address 207.244.227.91/32
Classification: LOW RISK
---
## EXECUTIVE SUMMARY
IP address 207.244.227.91 operates on Contabo cloud infrastructure (ASN 40021) with a risk score of 25 (Low Risk). The IP shows no active threat indicators, maintains cloud hosting infrastructure characteristics, and operates with minimal operational activity. Neighborhood analysis indicates a clean subnet environment with low abuse density.
---
## OWNERSHIP & INFRASTRUCTURE
- ASN: 40021
- Organization: Contabo Inc.
- Network Block: 207.244.224.0/20
- Infrastructure Type: CloudCompute
- Service Classification: Firewalled / No Services
- Geolocation: United States, Missouri (St. Louis)
- DNS PTR: vmi3285978.contaboserver.net
---
## RISK ASSESSMENT
| Metric | Value | Assessment |
|---|---|---|
| Risk Score | 25 | Low Risk |
| Abuse Confidence | Not Elevated | |
| Blacklist Status | 0 lists | Clean |
| DNSBL Listed | 1 of 8 lists | Minimal exposure |
| Operator Score | 0.1304 | Minimal |
Key Indicators:
- No known attack campaigns correlated
- No Tor/VPN/proxy activity detected
- No spam source classification
- Isolated DNS blacklist listing (1/8 total lists)
---
## OBSERVATION HISTORY
Analysis of 18 historical observations reveals:
- Latest Data: 2026-06-14
- Persistence: No persistent malicious activity observed
- Threat Persistence Days: 0
- Ownership Changes: 0
Signal evolution shows consistent cloud hosting classification with no degradation in reputation. The IP demonstrates stable infrastructure characteristics across the observation period.
---
## NETWORK RELATIONSHIPS
- DNS Associations: vmi3285978.contaboserver.net (24 relationship entries)
- Network Affiliations: CONTA-48 (multiple entries)
- Relationship Count: 24 total
The IP maintains typical cloud hosting DNS associations with no anomalous patterns.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 207.244.227.91/24
- Abuse Density: 0.5 (Low)
- Classification: mostly_clean
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 1
Neighbor Profile:
- 207.244.227.110: Risk Score 25, Authority Score 60
The subnet demonstrates minimal abuse characteristics. Only one sibling IP shows elevated authority scoring, but no high-risk activity detected within the /24 boundary.
---
## RECOMMENDED ACTIONS
Current Status: No immediate action required. The IP maintains low-risk characteristics consistent with legitimate cloud hosting infrastructure.
Monitoring Recommendations:
- Continue periodic observation
- Monitor for service port openings
- Watch for DNSBL listing changes
- Track subnet abuse density trends
Firewall Policy: Standard cloud hosting rules apply. No blocking recommended based on current risk profile.
---
## CONCLUSION
IP 207.244.227.91 represents a low-risk Contabo cloud hosting environment with no active threat indicators. The single DNSBL listing represents minimal exposure within a clean subnet neighborhood. SOC teams may treat this IP according to standard cloud infrastructure policies without elevated threat monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Contabo Inc. |
| ASN | AS40021 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vmi3285978.contaboserver.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | vmi3285978.contaboserver.net |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-12 09:41:00 UTC |
| Last Seen | 2026-06-27 21:16:30 UTC |
| Profile Built | 2026-06-28 15:22:18 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.