IPDebrief

84.247.183.157

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 84.247.183.157/32

## Executive Summary

IP 84.247.183.157 is a cloud-hosted resource associated with Contabo infrastructure (ASN 51167, organization: Johannes Selg). The IP registers as Moderate Risk (score: 50) with limited but notable threat indicators. No active services or open ports detected.

## Ownership & Infrastructure

## Risk Assessment

MetricValue
Risk Score50 (Moderate)
DNSBL Listings2 of 8 lists
Max SeverityHigh
Abuse Density (Subnet)0
Known AttackerNo
Tor Exit/ProxyNo

## Observed Threat Indicators

## Related Entities

## Historical Activity

## Recommended Actions

Given the moderate risk score and limited threat indicators, this IP does not require immediate blocking. However, recommend:

1. Passive Monitoring: Log traffic for correlation with other threat indicators

2. Block if: Outbound connections detected to known malicious destinations

3. Review: Monitor for service exposure changes

## Conclusion

This IP represents a low-to-moderate risk cloud hosting resource with minimal active threat indicators. The primary concern is DNSBL listing, but no persistent malicious activity or service exposure detected. SOC teams may monitor passively or block based on organization-specific policies for cloud hosting IPs.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionGrand Est
CityLauterbourg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationJohannes Selg
ASNAS51167
Network NameTT-20240115
CIDR Block84.247.160.0/19
RIRRIPE
CountryDE
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvmi3126367.contaboserver.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvmi3126367.contaboserver.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeMulti-Service Host
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
8080http-alttcpโ€”
8443https-alttcpโ€”
Closed Ports22, 25, 80, 443, 3389 (2 open / 7 scanned)
Serverkong/3.9.1
HTTP Titleโ€”

๐Ÿ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
โš ๏ธ
CN=localhost, OU=IT Department, O=Kong, L=San Francisco, S=California, C=US
Issued by CN=localhost, OU=IT Department, O=Kong, L=San Francisco, S=California, C=US
Self-signed: Yes
SANsNone
Valid From2026-07-09T18:30:36+00:00
Valid Until2046-07-04T18:30:36+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256ECDSA
Validity Period7300 days
Serial Number00B0F33F214FE5193DFB354D5382A5DEF1
ThumbprintF729BA7F1892ACF7FBDFF6787DE77C21FAC02F89

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
0%
00
routing
0%
00
services
0%
00
ownership
25%
12
reputation
0%
00
geolocation
25%
11
Overall8%23
Coverage: 2/6 dimensions ยท Data sufficiency: partial
Data CoherenceMixed Signals (68%) โ€” 2 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, DE
โš  TLS certificate claims US but primary geo says DE

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-08-09 10:51:48 UTC
Last Seen2026-08-27 10:01:26 UTC
Profile Built2026-08-29 04:37:21 UTC
Data FreshnessLive
Signal Types21
Total Observations22
๐Ÿ” 21 signal types ยท 22 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.