## Intelligence Briefing: 82.197.66.232
Executive Summary
IP address 82.197.66.232 presents a low-risk profile with a risk score of 25. The address operates within a Contabo cloud compute infrastructure (ASN 40021) and demonstrates minimal threat indicators across all observed signals.
Network Identity and Infrastructure
- Provider: Contabo (CloudCompute infrastructure)
- ASN: 40021
- Organization: Johannes Selg
- CIDR Block: 82.197.66.0/24 (inferred from profile data)
- Geolocation: DE (Germany), with inference coordinates at 51.17°N, 10.45°E
- Timezone: Europe/Berlin
Network Role and Services
The IP resolved to hostname vmi2545629.contaboserver.net via DNS reverse lookup, with forward confirmation successful. No open ports were detected, and the system is classified as firewalled with no active services exposed. The infrastructure type is marked as cloud computing with hosting capabilities enabled.
Threat Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Known Attacker Status: False
- Tor Exit Node: False
- Spam Source: False
- Blacklist Count: 0
- DNSBL Listings: 1 out of 8 total lists checked
- Known Campaigns: None detected
Observational History
The IP has generated 24 observations since last recorded activity. Most recent signals date from June 19, 2026. Historical analysis indicates:
- Operator score: 0.2609 (Basic classification)
- No persistent malicious activity detected
- Ownership changes: 0
- Threat observation count: 1
- The IP is not classified as persistently malicious
Network Neighborhood Analysis
The /24 subnet (82.197.66.0/24) shows:
- Abuse Density: 0
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Classification: Mostly clean
- Inherited Risk: 2
No high-risk neighboring IPs were detected within the immediate subnet range.
Relationship Graph
The IP maintains 39 relationships, primarily centered on:
- DNS associations with vmi2545629.contaboserver.net
- Network associations within the same network designation
Recommended Actions
No security actions or firewall rules are recommended at this time due to the low-risk classification. The IP does not warrant blocking or restrictive measures based on current signal data.
Conclusion
This IP address operates within a commercial cloud hosting environment (Contabo) with no active malicious indicators. The absence of open ports, zero blacklist entries, and minimal threat signals suggest legitimate hosting activity. SOC analysts may monitor but no immediate defensive actions are required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS40021 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi2545629.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi2545629.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-13 19:05:54 UTC |
| Last Seen | 2026-06-27 23:59:56 UTC |
| Profile Built | 2026-06-28 18:04:52 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.