# INTELLIGENCE BRIEFING: 84.247.129.208/32
Classification: Moderate Risk | Risk Score: 65/100 | Last Updated: 2026-06-17
## EXECUTIVE SUMMARY
IP address 84.247.129.208 is a cloud-hosted virtual machine instance associated with German hosting provider Contabo. The asset presents elevated risk (65/100) due to cloud hosting infrastructure characteristics and DNSBL listings, though no active malicious indicators or known campaign associations were detected. The subnet environment remains clean with zero abuse density.
## TECHNICAL PROFILE
| Attribute | Value |
|---|---|
| **IP Address** | 84.247.129.208/32 |
| **ASN** | 51167 (Contabo) |
| **Organization** | Johannes Selg |
| **Network** | TT-20240111 |
| **CIDR Block** | 84.247.128.0/20 |
| **Country** | Germany (DE) |
| **Location** | Lauterbourg, Grand Est |
| **Geolocation Confidence** | Plausible (400km radius) |
## INFRASTRUCTURE CHARACTERISTICS
- Infrastructure Type: Cloud Compute (VPS)
- Provider: Contabo
- DNS PTR: vmi3238089.contaboserver.net
- Service Status: Firewalled / No Services Detected
- Open Ports: None
- Reverse DNS: Forward confirmed
## THREAT ASSESSMENT
Current Threat Indicators:
- Blacklist Count: 0
- Abuse Confidence: Not scored
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
DNSBL Status: 3 out of 8 total lists
- This indicates some reputation concerns despite current blacklist absence
Historical Analysis:
- Total Observations: 19 signals
- Ownership Stability: No changes recorded
- Threat Persistence: 0 days
- Recent Activity: Monitoring signals observed through June 2026
## NETWORK CONTEXT
Subnet Analysis (84.247.129.0/24):
- Abuse Density: 0%
- Classification: Clean
- Active Threat Siblings: 0
- Total Siblings: 1
Relationship Graph:
- 6 total relationships identified
- DNS associations to contaboserver.net hostnames
- Network associations to TT-20240111 block
## TRAFFIC CHARACTERISTICS
- Hop Count: 12
- Average RTT: 116.2ms
- Minimum RTT: 108ms
- Traceroute Violations: 4 timed-out hops
- First Hop: 0.3ms
## RECOMMENDED ACTIONS
IMMEDIATE (Priority: High)
- Increase logging verbosity for traffic from this IP
- Review recent activity patterns and connection attempts
- Implement monitoring for anomalies
MITIGATION (Firewall Rules)
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 84.247.129.208 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 84.247.129.208 drop` |
| nginx | `deny 84.247.129.208;` |
| pfSense | Add `84.247.129.208/32` to block list |
| Cloudflare WAF | Block IP with description "IPDebrief risk score 65" |
| AWS WAF | Add IP to blocked addresses list |
## ANALYST NOTES
The elevated risk score (65/100) primarily reflects the cloud-hosted nature of the infrastructure and DNSBL associations rather than confirmed malicious activity. The subnet environment remains clean, suggesting no coordinated abuse. However, the combination of factors warrants defensive monitoring. No immediate threat indicators were identified, but the risk profile suggests implementing conservative blocking measures pending further observation.
Intelligence Confidence: Medium (based on available signals)
Recommended Handling: Monitor and evaluate against organizational threat baseline
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | TT-20240111 |
| CIDR Block | 84.247.128.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3238089.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3238089.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 9 | 12 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-11 03:02:06 UTC |
| Last Seen | 2026-06-21 18:32:55 UTC |
| Profile Built | 2026-06-21 18:36:14 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.