# IP Intelligence Briefing: 212.172.221.207/32
## Executive Summary
Target 212.172.221.207 is assessed as LOW RISK with no active threat indicators detected. The IP belongs to a clean subnet with zero abuse density and no associated malicious activity.
---
## Technical Profile
Network Ownership:
- ASN: 12312 (AS12312-MNT)
- Organization: TIS-D406966-NET
- CIDR Block: 212.172.221.0/24
- RIR Registry: RIPE
- Abuse Contact: abuse@webhoster.de
Geolocation:
- Country: Germany (DE)
- Region: Baden-Wurttemberg
- City: Mannheim / Frankfurt (varied by signal source)
- Coordinates: 51.17°N, 10.45°E
- Timezone: Europe/Berlin
Network Classification:
- Status: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
- DNS Resolution: No forward resolution
- Hosted Domains: 0
---
## Threat Assessment
Risk Scores:
- Overall Risk Score: 0/10
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
Threat Indicators:
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Abuse Confidence Score: Not applicable
Campaign Activity:
- Campaign Likelihood: None
- Correlated IPs: 0
- Certificate Matches: 0
---
## Observation History
Signal Timeline: 15 observations recorded (recent activity: 2026-07-22)
Key Observations:
- Ownership changes: 0
- Threat persistence days: 0
- Persistently malicious: No
- Threat observation count: 0
- Geolocation signals consistently indicate Germany (DE)
- Network RTT: 108-115ms average
- Geo-plausibility: Validated across multiple probes (5 probes)
---
## Neighborhood Analysis
Subnet: 212.172.221.0/24
- Abuse Density: 0.0 (Clean)
- Classification: Clean
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 0
---
## Relationships Graph
Associated Entities:
- Same Network: TIS-D406966-NET (2 entries)
- No external relationships to organizations, hostnames, or certificates identified
---
## Recommended Actions
Firewall Rules: No blocking required. IP does not meet criteria for negative security action.
SOC Analyst Notes:
- IP demonstrates no malicious behavior patterns
- Subnet shows no historical abuse activity
- Network infrastructure appears to be legitimate hosting/telecom infrastructure
- No threat intelligence correlation detected
Monitoring Recommendation: Continue standard monitoring. No elevated threat level warrants special attention.
---
Classification: UNCLASSIFIED
Briefing Date: Current
Analyst: IPDebrief Intelligence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | AS12312-MNT |
| ASN | AS12312 |
| Network Name | TIS-D406966-NET |
| CIDR Block | 212.172.221.0/24 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 8443 | https-alt | tcp | — |
| Closed Ports | 22, 25, 3389, 8080 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | freesurf.webhoster.ag |
| Valid From | 2026-07-27T11:45:39+00:00 |
| Valid Until | 2026-10-25T11:45:38+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS12312 |
| Network Prefix | 212.172.0.0/16 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Enabled |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:21:39 UTC |
| Last Seen | 2026-08-29 03:28:23 UTC |
| Profile Built | 2026-08-29 03:28:45 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 212.172.221.207
Who owns the IP address 212.172.221.207?
212.172.221.207 is registered to AS12312-MNT. The address falls within the 212.172.221.0/24 network block. Registration is held at RIPE.
Where is 212.172.221.207 located?
Geolocation data places 212.172.221.207 in Mannheim, Baden-Wurttemberg, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 212.172.221.207 malicious or safe?
212.172.221.207 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 212.172.221.207?
Responsive ports observed on 212.172.221.207 include 80, 443, 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.