IPDebrief

84.247.129.208

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 84.247.129.208/32

Classification: Moderate Risk | Risk Score: 65/100 | Last Updated: 2026-06-17

## EXECUTIVE SUMMARY

IP address 84.247.129.208 is a cloud-hosted virtual machine instance associated with German hosting provider Contabo. The asset presents elevated risk (65/100) due to cloud hosting infrastructure characteristics and DNSBL listings, though no active malicious indicators or known campaign associations were detected. The subnet environment remains clean with zero abuse density.

## TECHNICAL PROFILE

AttributeValue
**IP Address**84.247.129.208/32
**ASN**51167 (Contabo)
**Organization**Johannes Selg
**Network**TT-20240111
**CIDR Block**84.247.128.0/20
**Country**Germany (DE)
**Location**Lauterbourg, Grand Est
**Geolocation Confidence**Plausible (400km radius)

## INFRASTRUCTURE CHARACTERISTICS

## THREAT ASSESSMENT

Current Threat Indicators:

DNSBL Status: 3 out of 8 total lists

Historical Analysis:

## NETWORK CONTEXT

Subnet Analysis (84.247.129.0/24):

Relationship Graph:

## TRAFFIC CHARACTERISTICS

## RECOMMENDED ACTIONS

IMMEDIATE (Priority: High)

MITIGATION (Firewall Rules)

PlatformRule
iptables`iptables -A INPUT -s 84.247.129.208 -j DROP`
nftables`nft add rule inet filter input ip saddr 84.247.129.208 drop`
nginx`deny 84.247.129.208;`
pfSenseAdd `84.247.129.208/32` to block list
Cloudflare WAFBlock IP with description "IPDebrief risk score 65"
AWS WAFAdd IP to blocked addresses list

## ANALYST NOTES

The elevated risk score (65/100) primarily reflects the cloud-hosted nature of the infrastructure and DNSBL associations rather than confirmed malicious activity. The subnet environment remains clean, suggesting no coordinated abuse. However, the combination of factors warrants defensive monitoring. No immediate threat indicators were identified, but the risk profile suggests implementing conservative blocking measures pending further observation.

Intelligence Confidence: Medium (based on available signals)

Recommended Handling: Monitor and evaluate against organizational threat baseline

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
Region30
CityFjellhamar
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationJohannes Selg
ASNAS51167
Network NameTT-20240111
CIDR Block84.247.128.0/20
RIRRIPE
CountryDE
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvmi3238089.contaboserver.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvmi3238089.contaboserver.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
24%
22
routing
17%
11
services
17%
11
ownership
35%
23
reputation
17%
12
geolocation
35%
23
Overall24%912
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: NO, DE

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-06-11 03:02:06 UTC
Last Seen2026-06-21 18:32:55 UTC
Profile Built2026-06-21 18:36:14 UTC
Data FreshnessLive
Signal Types20
Total Observations22
๐Ÿ” 20 signal types ยท 22 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.