# IP Intelligence Briefing: 89.117.146.143/32
## Executive Summary
IP address 89.117.146.143 is classified as LOW RISK (risk score: 25/100) with no active threat indicators. The IP represents a Contabo cloud compute VPS instance hosted in St. Louis, Missouri, exhibiting benign network behavior. No immediate blocking or mitigation actions are warranted based on current intelligence.
## Ownership and Infrastructure
- Provider: Contabo (ASN 40021)
- Infrastructure Type: CloudCompute
- Network Classification: Hosting provider environment
- Geolocation: United States, Missouri, St. Louis (38.64°N, -90.2°W)
- BGP Prefix: 89.117.144.0/21 (Origin ASN: 40021)
- Route Stability: False (route changes detected in past 30 days)
## Network Role and Services
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: None
- HTTP Service: None
- Cloud/Proxy Assessment: Cloud infrastructure (true), not CDN/VPN/Proxy/Tor
## DNS and Resolution
- PTR Hostname: vmi3308215.contaboserver.net
- Forward Resolution: vmi3308215.contaboserver.net (forward confirmed)
- Hosted Domains: None
- Email Authentication: No SPF or DMARC records present
## Threat Intelligence Profile
- Abuse Confidence Score: Not applicable (clean)
- Blacklist Count: 0
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Known Campaigns: None
- Threat Feeds: None
- DNSBL Listed: 1 of 8 lists (minor listing)
## Neighborhood Analysis (89.117.146.0/24)
- Abuse Density: 0%
- Subnet Classification: Clean
- Total Siblings: 1
- Active Threat Siblings: 0
- Neighbor IP: 89.117.146.163 (risk score: 25)
- Risk Distribution: 1 low, 0 medium, 0 high
## Observation History (17 Observations)
Recent activity indicates stable, benign behavior:
- Latest Observation: 2026-06-15 (operator score: 0.2609)
- Threat Persistence: 0 days
- Persistent Malicious Activity: False
- Ownership Changes: 0
- Threat Observation Count: 1 (historical)
## Relationship Graph
31 relationships identified, primarily:
- DNS associations to vmi3308215.contaboserver.net
- Network associations to LRTC_INETNUM_RENT
- Multiple duplicate link types indicating consistent infrastructure mapping
## Security Recommendations
No immediate actions recommended. Current risk score (25) falls below threshold for automated blocking. The IP exhibits:
- No active threat indicators
- No open services or ports
- Clean neighborhood profile
- Consistent low-risk historical behavior
Monitoring Guidance: Maintain passive monitoring. No firewall rules or WAF policies required at this time. Consider periodic revalidation if this IP appears in threat feeds or exhibits behavioral changes.
---
*Intelligence generated by IPDebrief. Data current as of analysis timestamp.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Private Customer |
| ASN | AS40021 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vmi3308215.contaboserver.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vmi3308215.contaboserver.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 8% | 1 | 1 |
| Overall | 17% | 8 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 15:20:48 UTC |
| Last Seen | 2026-06-28 19:59:23 UTC |
| Profile Built | 2026-06-29 02:02:09 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.