IP INTELLIGENCE BRIEFING: 217.216.92.40/32
EXECUTIVE SUMMARY
IP address 217.216.92.40 is a Contabo cloud computing VPS instance with a Low Risk classification (Risk Score: 25). The IP belongs to ASN 40021 and network TT-20251105, registered under the organization "Johannes Selg." The endpoint operates within a clean subnet environment with minimal abuse density.
OWNERSHIP & INFRASTRUCTURE
- Provider: Contabo (CloudCompute infrastructure)
- ASN: 40021
- CIDR Block: 217.216.80.0/20
- Infrastructure Type: Cloud Hosting, Multi-Service Host
- Registration: RIR Ripe
GEOLOCATION
- Reported Location: Granada, DE (Europe/Berlin timezone)
- Coordinates: 51.17°N, 10.45°E
- Validation Status: GeoPlausible = False
- RTT Anomaly: Measured RTT of 23ms conflicts with geographic distance of 5,941km (minimum expected RTT: 118.8ms), suggesting geolocation data may be inaccurate or spoofed.
NETWORK SERVICES
- Open Ports: 80/TCP (HTTP), 3389/TCP (RDP)
- Server Fingerprint: nginx/1.24.0 (Ubuntu)
- DNS Resolution: vmi3297943.contaboserver.net
- SSL/TLS: No certificate detected
THREAT ASSESSMENT
- Risk Score: 25 (Low Risk)
- Threat Indicators: None detected
- Blacklist Status: Not listed on any threat feeds
- Campaign Association: No known campaigns or correlation
- Control Plane: DNSBL listed on 1 of 8 total lists; route stability flagged as false
HISTORICAL ANALYSIS
Analysis of 24 signal observations indicates stable infrastructure characteristics with no significant threat posture changes. The IP consistently classifies as cloud hosting with no escalation to malicious activity.
NEIGHBORHOOD CONTEXT
- Subnet: 217.216.92.0/24
- Abuse Density: Low (1.0)
- Classification: Mostly Clean
- Sibling IPs: 1 active neighbor, not flagged as malicious
RECOMMENDATIONS
No immediate blocking actions recommended. The IP presents as a legitimate cloud VPS with low-risk characteristics. However, the open RDP port (3389) represents a potential lateral attack vector and should be monitored. No firewall rules are required at this time.
ASSESSMENT: This endpoint is classified as a low-risk Contabo hosting instance with no active threat indicators. Standard monitoring procedures apply.
---
*Generated from IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS40021 |
| Network Name | TT-20251105 |
| CIDR Block | 217.216.80.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3297943.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3297943.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 443, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 00:20:06 UTC |
| Last Seen | 2026-06-29 07:00:58 UTC |
| Profile Built | 2026-06-29 07:04:25 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.