THREAT INTELLIGENCE BRIEFING
IP Address: 77.237.234.238/32
Date: 2026-06-14
Classification: Cloud Compute Infrastructure
Executive Summary
The IP address 77.237.234.238 is a cloud-hosted virtual machine instance operating on Contabo infrastructure (ASN 51167, RIPE). The asset presents low risk with a reputation score of 25/100. Current threat indicators show minimal malicious activity, with one DNSBL listing detected.
Ownership and Infrastructure
- Organization: Johannes Selg
- Provider: Contabo (Cloud Computing)
- ASN: 51167
- Country: DE (Germany)
- Geolocation: Benidorm (400km accuracy radius)
- Infrastructure Type: CloudCompute / Hosting
- PTR Hostname: vmi3170361.contaboserver.net
Network Characteristics
- Open Ports: TCP/80 (HTTP), TCP/22 (SSH)
- Server Fingerprint: nginx/1.14.0 (Ubuntu)
- HTTP Version: 1.1
- DNS Resolution: Forward confirmed to vmi3170361.contaboserver.net
- Email Authentication: SPF and DMARC records not configured
Threat Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence: Not elevated
- Blacklist Status: Listed on 1 of 8 DNSBL feeds
- Known Campaigns: None detected
- Tor/Proxy/VPN: Not identified
- Threat Observation Count: 1
Observation History
Signal monitoring over the past 30 days indicates 25 observations with consistent provider classification (Contabo). The IP shows no persistent malicious behavior. Most recent observation (2026-06-14) confirms cloud infrastructure classification. Subnet abuse density classified as "mostly_clean" with one threat sibling in the /24.
Related Entities
- DNS Associations: 46 relationships all mapping to vmi3170361.contaboserver.net
- Subnet Neighbors: 77.237.234.0/24 - Abuse density: 0, Classification: mostly_clean
- BGP Prefix: 77.237.232.0/21
Security Recommendations
- Traffic Volume: Standard monitoring recommended due to cloud hosting nature
- SSH Access: Verify SSH port 22 is not exposed to unauthorized access
- DNSBL Monitoring: Investigate origin of single DNSBL listing if traffic patterns are anomalous
- Cloud Context: This is a standard cloud VMI; false positives expected for benign cloud traffic
- Firewall Rule: No specific blocking required at this time based on current risk profile
Conclusion
This IP represents standard Contabo cloud hosting infrastructure with minimal threat indicators. The single DNSBL listing warrants monitoring but does not indicate active malicious use. SOC analysts should treat as low-priority cloud infrastructure traffic unless anomalous behavior patterns emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3170361.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3170361.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | nginx/1.14.0 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 17:41:46 UTC |
| Last Seen | 2026-06-27 16:31:50 UTC |
| Profile Built | 2026-06-28 10:36:45 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 30 |
Full dossier details are available via our API.