IP Intelligence Briefing: 5.189.153.106/32
Executive Summary
IP 5.189.153.106 is a Contabo cloud compute host located in Lauterbourg, Grand Est, Germany. The address presents a moderate risk profile (score 50) with no active threat indicators, but is DNSBL-listed on 2 of 8 total lists. The subnet is classified as clean with zero abuse density.
Ownership and Infrastructure
- ASN: 51167 (CONTABO)
- Organization: Johannes Selg
- Network Block: 5.189.144.0/20
- Infrastructure Type: CloudCompute / Hosting Provider
- Geolocation: Germany (DE), Lauterbourg, Grand Est (coordinates: 51.17°N, 10.45°E)
- Registration: RIR (RIPE)
Network Classification
- Is Cloud: Yes
- Is Hosting: Yes
- Connection Status: Firewalled / No Services
- Is Proxy: No | Is Tor: No | Is CDN: No
- Infrastructure Purpose: VPS/Cloud hosting
DNS and Network Fingerprint
- PTR Hostname: vmi3193619.contaboserver.net
- Forward Resolution: Confirmed
- Hosted Domains: 0
- Forward Hostnames: vmi3193619.contaboserver.net
- BGP Prefix: 5.189.144.0/20
- Route Stability: Unstable
Threat Intelligence Assessment
- Risk Score: 50 (Moderate Risk)
- Abuse Confidence Score: Not scored
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listings: 2 of 8 total lists
- Known Campaigns: None detected
- Threat Persistence Days: 0
Neighborhood Analysis
- Subnet: 5.189.153.106/24
- Abuse Density: 0%
- Classification: Clean
- Total Siblings: 1
- Threat Siblings: 0
- High/Medium Risk Neighbors: 0
Historical Observations
- Total Observations: 18
- Most Recent: 2026-06-22
- Ownership Changes: 0
- Persistently Malicious: No
- Signal Types Observed: Routing, reputation, geolocation, subnet classification, ownership
Network Relationships
- DNS Associations: vmi3193619.contaboserver.net (multiple)
- Network Associations: CONTABO (multiple)
Recommended Defensive Actions
Despite the moderate risk score and absence of active threat indicators, the following firewall rules are available for implementation:
- iptables: `iptables -A INPUT -s 5.189.153.106 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 5.189.153.106 drop`
- nginx: `deny 5.189.153.106;`
- pfSense: `5.189.153.106/32`
- Cloudflare WAF: Block with expression `ip.src eq 5.189.153.106`
- AWS WAF: CIDR `5.189.153.106/32`
Analyst Assessment
This IP addresses a Contabo cloud hosting environment. While current threat indicators are absent and the subnet shows clean classification, the moderate risk score and DNSBL listings warrant consideration for defensive blocking. The infrastructure is firewalled with no active services detected. No evidence of persistent malicious behavior or association with known threat campaigns. Recommend monitoring for any changes in threat indicators or subnet abuse patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 5.189.144.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3193619.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3193619.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 24% | 2 | 2 |
| Overall | 22% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-16 18:32:54 UTC |
| Last Seen | 2026-06-22 00:49:41 UTC |
| Profile Built | 2026-06-22 00:57:07 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.