IP Intelligence Briefing: 5.189.154.64
Risk Score: 25 (Low Risk) | Provider: Contabo (Cloud Hosting) | Geolocation: France
Key Findings:
1. Network Profile:
- Hosted on Contabo's infrastructure (CloudCompute), with no open services detected.
- Geolocated to Lauterbourg, France (MaxMind).
- Subnet 5.189.154.64/24 shows 1 high-risk neighbor (5.189.154.44, score 40) and 1 medium-risk neighbor (5.189.154.192, score 25). Subnet abuse density is low.
2. Threat Indicators:
- No malicious indicators, spam, or known attacker associations.
- DNS record linked to vmi3038876.contaboserver.net (Contabo-hosted domain).
- BGP analysis confirms stable routing with no recent changes.
3. Observation History:
- Recent activity includes DNS resolution and geolocation consistency.
- No persistent threat signals or honeypot interactions detected.
Recommendations:
- Monitor subnet neighbors for potential risk shifts, particularly 5.189.154.44.
- Verify DNS associations and ensure no unexpected subdomains are linked to this IP.
- Maintain baseline observation due to mixed-risk neighbors, though no immediate mitigation is required.
Next Steps:
- Cross-reference with internal threat feeds for any missed indicators.
- Reassess if neighborsβ risk scores change over time.
No firewall rules recommended at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 5.189.144.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vmi3038876.contaboserver.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vmi3038876.contaboserver.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-12 15:26:57 UTC |
| Last Seen | 2026-06-21 19:55:54 UTC |
| Profile Built | 2026-06-21 20:03:36 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.