# IP INTELLIGENCE BRIEFING: 38.242.155.229/32
Classification: Low Risk | Date: 2026-06-20 | Analyst: IPDebrief Intelligence
---
## EXECUTIVE SUMMARY
IP address 38.242.155.229 operates as a cloud-based virtual machine under Contabo infrastructure with an overall risk score of 25 (Low Risk). The IP resolves to hostname vmi3065672.contaboserver.net and exhibits mixed geolocation signals between the United States and France. No active services or open ports detected. No specific firewall rules required at this time.
---
## OWNERSHIP & NETWORK CLASSIFICATION
- Provider: Contabo GmbH (Cloud Compute Infrastructure)
- Organization: Cogent Communications, LLC
- ASN: 51167 (COGENT-A)
- RIR: RIPE NCC
- Infrastructure Type: Cloud Hosting / Virtual Machine
- BGP Prefix: 38.242.152.0/21
- Route Stability: Stable (0 route changes in 30 days)
---
## GEOLOCATION ANALYSIS
Geolocation data shows conflicting signals:
- Consensus Location: US (primary) with secondary France/Lauterbourg signals
- Confidence: Mixed (35-90% confidence across sources)
- Observation Count: 27 total signals
- Geographic Discrepancy: Notable variance between US and European geolocation databases
---
## THREAT INDICATORS
- Overall Risk Score: 25/100 (Low Risk)
- Abuse Confidence: Not flagged
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0 (DNSBL: 1 of 8 lists)
- Campaign Associations: None detected
- Threat Persistence: 0 days (not persistently malicious)
---
## OBSERVATION HISTORY (Key Findings)
Analysis of 27 historical observations reveals:
- June 15, 2026: Cloud computing infrastructure identification confirmed
- Geolocation Signals: Mixed US/France attribution across different databases
- Risk Signals: Individual signals ranged 35-66 risk scores
- Proxy Detection: Multiple signals flagged as proxy/VPN services
- Recent Activity: No significant escalation in threat posture
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 38.242.155.229/24
- Abuse Density: 0 (Clean subnet)
- Classification: Mostly Clean
- Threat Siblings: 1 detected
- Active Siblings: 0
- Overall Assessment: Neighborhood shows minimal abuse indicators
---
## NETWORK SERVICES
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Banner: Not available
- Email Reputation: No evaluation available
- Service Classification: Firewalled / No Active Services
---
## RELATIONSHIPS & EVIDENCE
- DNS Associations: vmi3065672.contaboserver.net (repeated)
- Network Associations: COGENT-A (Cogent backbone)
- Total Relationship Count: 40 entries
- Evidence Quality: Standard commercial DNS resolution
---
## SECURITY RECOMMENDATIONS
Action Required: None
- Risk score (25) does not warrant blocking
- No specific firewall rules generated
- Continue standard monitoring
- No immediate threat mitigation needed
---
## CONCLUSION
This IP represents a standard cloud hosting environment under Contabo with no active threat indicators. The mixed geolocation signals warrant awareness but do not indicate malicious activity. Subnet analysis confirms clean neighborhood conditions. No blocking or firewall rules recommended.
Recommendation: Monitor, do not block.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cogent Communications, LLC |
| ASN | AS51167 |
| Network Name | β |
| CIDR Block | 38.242.152.0/21 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vmi3065672.contaboserver.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vmi3065672.contaboserver.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 24% | 2 | 3 |
| ownership | 24% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 27% | 12 | 20 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-15 14:46:16 UTC |
| Last Seen | 2026-06-28 02:32:13 UTC |
| Profile Built | 2026-06-28 20:37:51 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 32 |
Full dossier details are available via our API.