# IP Intelligence Briefing: 213.136.85.104/32
## Executive Summary
IP 213.136.85.104 is a low-risk (Risk Score: 25) CloudCompute infrastructure address registered to Contabo (ASN 51167) in Nuremberg, Germany. The IP shows stable network characteristics with no active threat indicators, no malicious reputation, and minimal neighborhood contamination. No immediate blocking action is recommended.
## Network Profile
| Attribute | Value |
|---|---|
| **IP Address** | 213.136.85.104/32 |
| **Provider** | Contabo |
| **ASN** | 51167 |
| **Organization** | Johannes Selg |
| **Country** | DE (Germany) |
| **Region** | Bavaria (BY) |
| **City** | Nuremberg |
| **Infrastructure Type** | CloudCompute |
| **Hosting Provider** | Contabo |
| **DNS Reverse** | vmi3119602.contaboserver.net |
| **Open Ports** | None detected |
| **Services** | None active |
## Threat Assessment
- Overall Risk Score: 25 (Low)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Association: None detected
## Neighborhood Analysis
- Subnet: 213.136.85.104/24
- Abuse Density: 0 (Clean)
- Classification: Mostly Clean
- Active Siblings: 2
- Threat Siblings: 2
- Neighbor Risk: 213.136.85.216 (Risk Score: 25, Authority Score: 60)
- Conclusion: Minimal neighborhood contamination; peer IP also low-risk
## Historical Signals
- Total Observations: 26
- Threat Persistence: 0 days (Not persistently malicious)
- Route Stability: Stable (no changes in last 30 days)
- BGP Origin: 51167 (Consistent since 2010-06-11, 5,851 days)
- Prefix: 213.136.84.0/23 (Stable)
- Recent Classification: Mostly Clean
- DNSBL Listing: 1 of 8 lists (likely non-malicious listing)
## Observed Relationships
- Network: CONTABO (multiple associations)
- Hostname: vmi3119602.contaboserver.net
- Total Relationships: 37
- Primary Association: Virtual Machine Instance (VMI) on Contabo infrastructure
## Recommended Actions
- Firewall Policy: Monitor/Allow (Low risk profile)
- Threat Intelligence: No blocking required
- Monitoring Priority: Low
- Note: Standard logging and traffic monitoring recommended per organization policy
## Intelligence Confidence
All data points corroborate a benign cloud hosting endpoint. The IP demonstrates stable infrastructure characteristics typical of legitimate cloud services. No escalation of threat level is warranted based on current signals.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | 213.136.84.0/23 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3119602.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3119602.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 24% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:11 UTC |
| Last Seen | 2026-06-27 04:09:26 UTC |
| Profile Built | 2026-06-27 22:15:33 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 31 |
Full dossier details are available via our API.