## IP Intelligence Briefing: 84.247.128.207/32
Classification: Low Risk - Cloud Infrastructure Node
Date: Current Intelligence Cycle
Executive Summary
IP address 84.247.128.207 is a low-risk (score: 25/100) cloud compute endpoint operated by Contabo under AS51167. The IP resolves to a virtual machine instance (vmi3015802.contaboserver.net) within the Contabo hosting infrastructure. No active threat indicators, blacklist entries, or malicious campaign associations detected.
Key Findings
Infrastructure Profile
- Organization: Johannes Selg (Owner)
- Provider: Contabo (CloudCompute/Hosting)
- ASN: 51167 (RIPE RIR)
- CIDR Block: 84.247.128.0/20
- Geolocation: Germany (DE), Fjellhamar region (400km accuracy radius)
- Network Role: Firewall-protected cloud server, no open services detected
Threat Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence: None detected
- Blacklist Count: 0
- Known Campaigns: None
- Tor/Proxy/VPN: Negative
- DNSBL Listings: 1 of 8 (minimal impact)
Observation History
23 total observations recorded. Most recent activity: 2026-06-18. Historical data shows geolocation inconsistencies between DE and NO sources, typical for cloud-hosted infrastructure with dynamic routing. Subnet abuse density rated 0.5 (moderate), with classification "mostly_clean."
Relationship Analysis
58 relationships identified, including:
- Multiple same-network associations (TT-20240111 network identifier)
- DNS association with vmi3015802.contaboserver.net
- No certificate or hostname campaign indicators
Neighborhood Assessment
Subnet 84.247.128.0/24 contains 2 total IPs:
- Target: 84.247.128.207 (risk: 25, low)
- Neighbor: 84.247.128.250 (risk: 0, low)
- Abuse Density: 0.0
- Classification: Mostly clean
Recommended Actions
No specific mitigation actions required at this time. Standard cloud infrastructure monitoring procedures apply. If traffic patterns change or threat indicators emerge, re-evaluate against Contabo's abuse reporting guidelines.
Analyst Notes: This IP represents typical cloud hosting infrastructure. The absence of open services, zero blacklist entries, and low risk score suggest legitimate commercial use. Monitor for any behavioral changes that would elevate threat classification.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3015802.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3344491.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:37 UTC |
| Last Seen | 2026-06-27 09:32:38 UTC |
| Profile Built | 2026-06-28 03:38:57 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.