IPDebrief

80.241.208.225

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 80.241.208.225

## Executive Summary

IP address 80.241.208.225 is a low-risk virtual machine instance hosted on CONTABO cloud infrastructure. The address resolves to vmi3262454.contaboserver.net and presents minimal threat indicators. Risk score of 25/100 indicates low-risk classification with no active campaign associations.

## Technical Profile

Network Ownership: ASN 51167 (CONTABO), registered to Johannes Selg under RIR RIPE. CIDR block: 80.241.208.0/21.

Geolocation: Lauterbourg, Grand Est, Germany (DE). Coordinates: 51.17°N, 10.45°E. Geolocation validation confirmed plausible with 400km accuracy radius. Round-trip time measurements: 108-113ms.

Infrastructure Classification: CloudCompute hosting environment. Single-service virtual machine instance. Not identified as CDN, VPN, proxy, or Tor exit node.

DNS Resolution: Forward resolution confirms vmi3262454.contaboserver.net. PTR record matches forward lookup. No SPF or DMARC records configured for the domain.

## Service Exposure

Port 22 (SSH) is actively listening with banner: SSH-2.0-OpenSSH_8.7. No HTTP services detected. No TLS certificates in use.

## Threat Assessment

Current Risk Level: Low Risk (Score: 25)

DNSBL Analysis: Single listing detected across 8 total blacklist sources. No correlation to active threat campaigns.

## Network Neighborhood

Subnet analysis for 80.241.208.0/24:

Neighbor IP: 80.241.208.124 (Risk Score: 25, Authority Score: 60). This sibling represents a low-risk CONTABO deployment.

## Relationship Graph

Primary associations:

No evidence of shared infrastructure with malicious entities or campaign coordination.

## Historical Analysis

Signal observation history shows 20 recent observations with no persistent malicious behavior. Key findings:

Temporal analysis indicates stable ownership and no escalation in threat activity over the observation window.

## Recommended Actions

Network Defense:

Threat Monitoring:

Classification:

## Conclusion

IP 80.241.208.225 represents a legitimate CONTABO cloud virtual machine with minimal threat indicators. The address shows no evidence of malicious activity, campaign participation, or infrastructure sharing with known bad actors. Standard monitoring and CONTABO-specific infrastructure awareness apply. No immediate defensive actions required beyond normal operational procedures for cloud hosting providers.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionGrand Est
CityLauterbourg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationJohannes Selg
ASNAS51167
Network NameCONTABO
CIDR Block80.241.208.0/21
RIRRIPE
CountryDE
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvmi3262454.contaboserver.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvmi3262454.contaboserver.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.7

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
17%
11
services
24%
22
ownership
35%
23
reputation
17%
12
geolocation
35%
23
Overall27%1014
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-06-14 14:14:25 UTC
Last Seen2026-06-21 22:12:47 UTC
Profile Built2026-06-21 22:15:06 UTC
Data FreshnessLive
Signal Types21
Total Observations22
๐Ÿ” 21 signal types ยท 22 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.