# IP Intelligence Briefing: 62.84.185.52
## Executive Summary
IP 62.84.185.52 operates as a CloudCompute host on Contabo infrastructure (ASN 51167) within a high-abuse subnet environment. Current risk assessment indicates Moderate Risk (score: 40) with elevated neighborhood context suggesting potential abuse activity.
## Technical Profile
- IP Address: 62.84.185.52/32
- Risk Score: 40 (Moderate)
- Provider: Contabo (ASN 51167)
- Infrastructure Type: CloudCompute / Single-Service Host
- Geolocation: Shrewsbury, ENG (Germany)
- DNS Resolution: linux04.r00tbase.de (r00tbase.de domain)
- Open Ports: TCP/22 (SSH - OpenSSH_9.6p1 Ubuntu)
- Network Role: Hosting provider infrastructure
## Neighborhood Analysis
Subnet 62.84.185.0/24 exhibits high abuse density (71.43%), with 7 active sibling IPs:
- 5 classified as threats
- 6 neighbors with risk scores 40-50
- Inherited risk score: 12
Neighbor distribution indicates medium-risk activity concentrated across the /24 block.
## Threat Indicators
- Blacklist Status: 0 direct listings
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
## Historical Observations
Analysis of 25 signal observations (most recent: 2026-06-23):
- Subnet-level abuse density signals present
- Threat observation count: 1
- Ownership changes: 0
- Not classified as persistently malicious
## Recommended Actions
Based on moderate risk profile and neighborhood context:
1. Monitor inbound SSH (TCP/22) traffic from 62.84.185.0/24 for anomalous activity
2. Block or rate-limit traffic from high-risk neighbors (62.84.185.55, .56, .60, .63, .67, .69) showing risk scores of 50
3. Review DNS resolution patterns for r00tbase.de domain if legitimate use not confirmed
4. Implement connection rate limiting for SSH sessions from this subnet
5. Consider temporary blocking if specific threat indicators emerge from neighborhood analysis
## Intelligence Notes
While the target IP shows no direct threat indicators, its position within a high-density abuse subnet warrants defensive posture. The infrastructure classification (Contabo cloud hosting) combined with the domain name pattern suggests potential hosting of legitimate or borderline services. SOC analysts should correlate with organizational context before taking restrictive action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | linux04.r00tbase.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | linux04.r00tbase.de |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:31 UTC |
| Last Seen | 2026-06-27 09:02:44 UTC |
| Profile Built | 2026-06-28 03:08:06 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.