# IP Intelligence Briefing: 84.247.173.58
## Executive Summary
IP address 84.247.173.58 is a low-risk cloud compute endpoint hosted by Contabo in Germany. The address resolves to a virtual machine container with minimal threat indicators and no active malicious campaigns. While the subnet shows some inherited risk from neighboring IPs, this specific endpoint demonstrates stable, benign behavior.
## Network Profile
- IP Address: 84.247.173.58/32
- Risk Score: 25 (Low Risk)
- Provider: Contabo (ProviderScore: 0)
- Infrastructure Type: CloudCompute / Hosting
- Country: Germany (DE)
- Region: Grand Est
- City: Lauterbourg
- ASN: AS51167
- Organization: Johannes Selg
## DNS & Hostname Intelligence
The IP resolves to the hostname `vmi3012952.contaboserver.net`, indicating it is a virtual machine instance on Contabo's infrastructure. Forward and reverse DNS resolution confirm the hostname association. The domain does not implement SPF or DMARC authentication records.
## Threat Assessment
- Threat Indicators: None detected
- Blacklist Status: Listed on 1 of 8 DNSBL checks
- Campaign Affiliation: No known campaign associations
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
## Service Exposure
Port scanning and service enumeration indicate no open ports are currently accessible. The endpoint appears firewalled with no exposed services. HTTP probing returned a 200 status with nginx/1.27.5 server banner.
## Network Neighborhood Analysis
Subnet 84.247.173.0/24 shows:
- Abuse Density: 1
- Classification: Mostly clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
One threat sibling exists within the /24 block, though this endpoint maintains low-risk characteristics.
## Control Plane Intelligence
- BGP Prefix: 84.247.160.0/19
- Route Stability: Unstable (changes detected)
- RPKI State: Not validated
- DNSSEC: Valid
- Delegation Age: Unknown
## Observation History
Analysis of 22 historical observations reveals consistent provider identification as Contabo across multiple signal types. Geolocation data consistently places the endpoint in Germany. One observation noted ASN AS29286 skylogic s.p.a. from Norway, suggesting potential multi-ISP routing. Recent observations from June 2026 show no significant changes in risk posture.
## Recommended Security Actions
Based on the low-risk profile, no immediate blocking or mitigation actions are required. Standard monitoring practices are appropriate. If this IP appears in traffic logs, it may be safely allowed with standard logging for baseline traffic analysis.
## SOC Analyst Notes
- The hostname pattern `vmi3012952.contaboserver.net` indicates a standard VPS/container instance.
- Low risk score (25) and lack of threat indicators support benign classification.
- Single DNSBL listing requires contextual investigation if observed in suspicious traffic patterns.
- Monitor for any changes in port exposure or service behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3012952.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3012952.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | nginx/1.27.5 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-15 14:46:54 UTC |
| Last Seen | 2026-06-28 02:38:35 UTC |
| Profile Built | 2026-06-28 20:43:29 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.