# IP Intelligence Briefing: 75.119.134.84/32
Classification: Low Risk / Cloud Infrastructure
## Executive Summary
IP 75.119.134.84 is a low-risk cloud compute instance hosted on Contabo infrastructure in Germany. The IP shows minimal threat indicators, no persistent malicious activity, and operates within a clean subnet environment. Recommended treatment: monitor with standard logging, no immediate blocking required.
---
## Network Identity & Infrastructure
- IP Address: 75.119.134.84/32
- ASN: 51167 (Contabo)
- Organization: Johannes Selg / CONTABO
- CIDR Block: 75.119.128.0/20
- Geolocation: Lauterbourg, Grand Est, Germany (DE)
- Infrastructure Type: Cloud Compute / Cloud Hosting
- DNS Hostname: vmi3293540.contaboserver.net (Virtual Machine Instance)
---
## Risk Assessment
- Overall Risk Score: 25/100 (Low Risk)
- Provider Risk Score: 0
- Authority Risk Score: 0
- Stability Score: 0
Threat Indicators:
- No known attacker associations
- Not a Tor exit node or proxy
- Not identified as spam source
- Zero blacklist entries
- One DNSBL listing out of 8 total lists
- No known campaign correlations
---
## Neighborhood Analysis
Subnet: 75.119.134.84/24
- Abuse Density: 0 (clean)
- Active Siblings: 2
- Threat Siblings: 3
- Classification: Mostly Clean
Adjacent IPs:
| IP Address | Risk Score | Status |
|---|---|---|
| 75.119.134.130 | 25 | Low Risk |
| 75.119.134.234 | 25 | Low Risk |
No high or medium-risk neighbors detected. Subnet shows minimal abuse correlation.
---
## Historical Observations
Total Observations: 21
Observation Period: Recent activity tracked through 2026-06-21
Key Trends:
- No ownership changes detected
- No persistent malicious activity observed
- Threat persistence: 0 days
- Threat observation count: 1
- Network classification consistently: mostly_clean
- Inherited risk score: 7/100
Signal Confidence:
- Network classification: 0.40 confidence
- Ownership stability: 0.85 confidence
- Threat indicators: 0.20 confidence
- Infrastructure type: 0.90 confidence
---
## Relationship Graph
- Total Relationships: 31
- Primary Associations: CONTABO network infrastructure
- DNS Associations: vmi3293540.contaboserver.net
- No anomalous cross-network or cross-ownership relationships detected
---
## Service & Network State
- Open Ports: None detected
- TLS Certificate: Not available
- HTTP Service: No banner/title detected
- Connection Type: N/A
- Route Stability: False (route changes observed in 30d)
- BGP Prefix: 75.119.128.0/19
- RPKI State: Not validated
---
## Recommended Actions
Immediate: No blocking required
Monitoring: Standard logging with Contabo infrastructure
Firewall Rules: Not recommended (low risk profile)
Investigation Priority: Low
---
## Intelligence Notes
This IP represents a standard cloud compute instance on Contabo's infrastructure. The low risk score (25), clean neighborhood classification, and absence of persistent threat indicators indicate legitimate hosting activity. The single DNSBL listing warrants monitoring but does not warrant immediate blocking. The IP's association with a virtual machine hostname (vmi3293540.contaboserver.net) confirms cloud infrastructure deployment.
Assessment: Legitimate cloud hosting IP with no actionable threat indicators. Treat as benign infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 75.119.128.0/20 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3293540.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3293540.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 17:04:13 UTC |
| Last Seen | 2026-06-29 08:00:10 UTC |
| Profile Built | 2026-06-29 08:03:47 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.