# IP Intelligence Briefing: 75.119.156.20/32
Classification: LOW RISK
Date: 2026-06-21
Analyst: IPDebrief Intelligence
---
## Executive Summary
IP 75.119.156.20 is a low-risk cloud infrastructure endpoint hosted by CONTABO (AS51167) in Düsseldorf, Germany. The address demonstrates consistent operational behavior with no active threat indicators. Risk assessment score: 25/100.
---
## Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 51167 (Johannes Selg / CONTABO) |
| **Organization** | CONTABO |
| **CIDR Block** | 75.119.144.0/20 |
| **Infrastructure Type** | CloudCompute / Hosting |
| **Geolocation** | Düsseldorf, Germany (51.17°N, 10.45°E) |
| **Registration** | ARIN |
---
## Network Role & Services
- Role: Cloud VPS / Web Server
- Open Ports: 80 (HTTP), 443 (HTTPS)
- Web Server: nginx/1.28.0
- Application Stack: Next.js
- TLS Certificate: Let's Encrypt (CN=app.techtots.edu.gh)
- Security Features: HSTS enabled, HTTP/2 disabled, Content-Type header protection active
---
## Threat Indicators
Current Status: CLEAN
| Indicator | Value |
|---|---|
| **Risk Score** | 25 (Low) |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 1 of 8 lists |
| **Known Attacker** | False |
| **Spam Source** | False |
| **Tor Exit Node** | False |
| **Active Campaigns** | None |
---
## Neighborhood Analysis (75.119.156.0/24)
- Abuse Density: 0.5 (Low)
- Classification: mostly_clean
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 1
- Neighbor IP: 75.119.156.116 (Risk: 25)
The subnet demonstrates minimal abuse activity with a single threat-related sibling IP identified.
---
## Observation History (25 Signals)
Temporal Pattern: Consistent cloud infrastructure behavior observed since June 16, 2026.
Key Observations:
- June 21, 2026: DNS resolution to edu.gh domain, SPF/DMARC records present
- June 16, 2026: Full service fingerprinting completed
- TLS 1.3 with TLS_AES_256_GCM_SHA384 cipher
- Server response time: 945ms average
- HSTS header: max-age=31536000; includeSubDomains
- Same-origin policy: SAMEORIGIN
- X-Content-Type-Options: nosniff
Stability Assessment: No ownership changes detected. Infrastructure classified as persistently benign.
---
## Relationship Graph
Total Relationships: 26
- Network Associations: 13 unique CONTABO network references
- DNS Associations: 9 references to vmi2818997.contaboserver.net
No anomalous external relationships detected. All associations confirm legitimate cloud hosting infrastructure.
---
## Recommended Actions
Firewall/Security Rules: No blocking required. IP demonstrates benign operational patterns.
Monitoring Recommendations:
- Maintain passive observation for continued low-risk classification
- Monitor for any sudden risk score escalation
- Track DNSBL list additions if any occur
---
## Conclusion
IP 75.119.156.20 represents a standard cloud hosting endpoint with minimal security risk. The address shows consistent operational behavior, proper security headers, and no threat indicators. SOC teams may treat as benign but should maintain standard monitoring practices for cloud infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | CONTABO |
| CIDR Block | 75.119.144.0/20 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi2818997.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi2818997.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 0/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.28.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | app.techtots.edu.gh |
| Valid From | 2026-05-02T09:15:28+00:00 |
| Valid Until | 2026-07-31T09:15:27+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 052A5D7F46B9255B89AF2FD647D0087290F0 |
| Thumbprint | FAD3424AEA2E5776581999C5C8C68D91E0351927 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 32% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 28% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-01 17:54:41 UTC |
| Last Seen | 2026-06-21 07:59:20 UTC |
| Profile Built | 2026-06-21 08:03:51 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.