IP Intelligence Briefing: 45.67.217.1
*Last Updated: 2026-06-14*
---
**Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Registered to Johannes Selg (ASIN 51167) under ARIN. Abuse contact available via RDAP.
- Geolocation: Lauterbourg, Grand Est, Germany (51.17°N, 10.45°E).
- Network Role: Cloud compute instance operated by Contabo, hosting a web server.
- Services:
- HTTP/HTTPS (ports 80/443) with Nginx 1.24.0.
- SSH (port 22) with OpenSSH 9.6.
- Valid TLS certificate (Letβs Encrypt) for magaziner.md.
---
**Threat Indicators**
- No active threats: No malicious indicators, spam, or known attacker associations.
- DNS: Resolves to contaboserver.net (no SPF/DMArc records).
- Subnet: Part of 45.67.217.1/24, with 1 active sibling IP (45.67.217.113, risk score 25).
---
**Observation History**
- Recent Activity:
- DNS resolution for magaziner.md and contaboserver.net (June 14, 2026).
- Network classification as "mostly_clean" with stable infrastructure.
- Long-Term Trends: No persistent malicious activity detected.
---
**Relationships**
- DNS Associations: Linked to vmi3294390.contaboserver.net.
- Network Neighbors: Subnet 45.67.217.1/24 has 2 IPs, 1 flagged as risky.
- Certificates: TLS certificate for magaziner.md (subject: magaziner.md, issuer: Letβs Encrypt).
---
**Recommendations**
1. Monitor Subnet: Track neighbor IP 45.67.217.113 for potential lateral movement.
2. Validate DNS: Confirm ownership of contaboserver.net to ensure no spoofing.
3. SSL/TLS: Verify Letβs Encrypt certificate validity for magaziner.md.
4. Network Segmentation: Isolate cloud instances to limit potential exposure.
---
Conclusion: This IP is associated with a legitimate Contabo cloud server, showing no immediate malicious behavior. However, its subnet contains a sibling IP with similar risk scores, warranting further investigation. Standard security practices should be applied to ensure DNS and network integrity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vmi3294390.contaboserver.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vmi3294390.contaboserver.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | magaziner.mdwww.magaziner.md |
| Valid From | 2026-05-14T15:52:58+00:00 |
| Valid Until | 2026-08-12T15:52:57+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 069C5FEAC7C1ABF45231F0E79311E20F9834 |
| Thumbprint | E6A75F8A485BD5C69A91634FDDF5902DC09CA582 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 25% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-13 19:05:21 UTC |
| Last Seen | 2026-06-27 23:52:52 UTC |
| Profile Built | 2026-06-28 23:58:00 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.