IP Intelligence Briefing: 37.60.230.103
*Generated via IPDebrief Threat Intelligence Platform*
---
**1. Core Profile**
- Risk Score: 0 (Low Risk)
- Provider: Contabo (Cloud Compute Hosting)
- Ownership: Johannes Selg (AS51167, RIPE)
- Geolocation: Germany (DE), Lauterbourg, 51.17°N 10.45°E
- Network Role: CloudCompute (firewalled, no public services)
- Threat Indicators: No active threats, no blacklist entries, not a Tor exit node
---
**2. Observation History**
- Recent Activity:
- Observed in Chicago, IL (US) with threat indicators (pulse_count=3, unknown pulse names).
- Mixed geolocation signals: 11 observations over 5 months (last updated 2026-06-11).
- Stability: Route instability detected (BGP route changes, low operator score).
- Consistency: 21 total observations; 16% of signals flagged as "high" risk.
---
**3. Relationships & Context**
- DNS Associations:
- Resolves to `vmi3222272.contaboserver.net` (Contabo VM).
- No email auth (SPF/DKIM) detected.
- Network Links:
- Subnet: `37.60.230.103/24` (abuse density: 1/100).
- No malicious neighbors detected.
- Provider: Contabo (cloud hosting) with no recent abuse reports.
---
**4. Behavioral Flags**
- Geolocation Discrepancy: IP registered in Germany but observed in the U.S. with threat signals.
- Route Stability: Unstable BGP routes (route changes in last 30 days).
- Ownership: Static ASN (AS51167) with no ownership changes.
---
**5. Recommendations**
- Monitor: Track geolocation anomalies and BGP route stability.
- Verify: Cross-check DNS resolution (`vmi3222272.contaboserver.net`) with internal hostnames.
- Block: Consider blocking if threat signals persist or if the IP is used for lateral movement.
- Context: Low-risk profile may mask dynamic cloud environments; validate against internal threat feeds.
---
*End of Briefing*
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | TT-20240125 |
| CIDR Block | 37.60.224.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3222272.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3222272.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.2 |
๐ TLS Certificate
| SANs | beshagroexport.uz |
| Valid From | 2026-06-01T11:45:09+00:00 |
| Valid Until | 2026-08-30T11:45:08+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 0572CDEB8DFBCCB12F0BE178CB36D6903F44 |
| Thumbprint | 0ACCF6312F74B049F046EA6933170918B7C3EA8A |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 15% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-29 18:15:05 UTC |
| Last Seen | 2026-06-29 06:44:36 UTC |
| Profile Built | 2026-06-29 06:53:00 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.