# IP Intelligence Briefing: 89.117.16.117/32
## Executive Summary
Intellectually assessed as Low Risk with a risk score of 25. The IP address resolves to a Contabo cloud hosting infrastructure in Seattle, WA, US, operating as a virtual machine instance with no open services detected. The IP exhibits minimal malicious indicators but maintains a DNSBL listing that warrants monitoring.
## Infrastructure Profile
- IP Address: 89.117.16.117
- Risk Score: 25 / 100 (Low Risk)
- Provider: Contabo (ASN 40021)
- Organization: Private Customer
- Network Classification: CloudCompute, Hosting Infrastructure
- Geolocation: Seattle, WA, US (2500km accuracy radius)
- Infrastructure Type: Cloud Server (Firewalled / No Services)
## DNS Resolution
- PTR Record: vmi2876361.contaboserver.net
- Forward Resolution: Confirmed (1 hostname)
- Email Authentication: SPF not configured, DMARC not configured
## Threat Assessment
- Abuse Confidence Score: Not available
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Associated Campaigns: None detected
- Threat Feeds: No matches
## Network Behavior
- Open Ports: None detected
- Services: None running (firewalled)
- TLS Certificate: None
- HTTP Banner: None
- Route Stability: Stable (no changes in 30 days)
- BGP Prefix: 89.117.16.0/21
- AS Path: 293 3356 40021
- IRR Consistency: Mismatch (potential misconfiguration)
## Neighborhood Analysis (89.117.16.0/24)
- Abuse Density: 1 (low)
- Classification: Mostly Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Inherited Risk: 2 (low)
## Relationship Graph
- DNS Associations: vmi2876361.contaboserver.net
- Network Relationships: LRTC_INETNUM_RENT
- Total Relationships: 48 (primarily DNS and network-level associations)
## Historical Observations
- Total Observations: 27 signals
- Latest Signal: 2026-06-15T05:23:26 UTC
- Observation Pattern: Consistent cloud hosting classification
- Threat Persistence: No persistent malicious behavior detected
- Campaign Likelihood: None
## Recommended Actions
1. Monitor DNSBL Listing: Investigate the single DNSBL listing to determine the reason for listing
2. Verify IRR Mismatch: Confirm if the IRR inconsistency requires correction with the registry
3. Passive Monitoring: Continue passive observation; no immediate blocking required
4. Traffic Analysis: If this IP appears in traffic logs, analyze for anomalous patterns despite low-risk profile
## Threat Level Assessment
This IP represents a standard Contabo VPS instance with minimal threat indicators. The low risk score (25), absence of open services, and lack of malicious campaign associations suggest benign cloud hosting usage. However, the DNSBL listing and IRR inconsistency warrant periodic review to ensure no policy violations or security issues have developed.
Classification: Low Risk - Cloud Hosting Infrastructure
Recommended Action: Monitor / Passive Observation
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Private Customer |
| ASN | AS40021 |
| Network Name | β |
| CIDR Block | 89.117.16.0/21 |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vmi2876361.contaboserver.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | vmi2876361.contaboserver.net |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 27% | 3 | 4 |
| services | 15% | 2 | 2 |
| ownership | 27% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 23% | 13 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-17 03:09:46 UTC |
| Last Seen | 2026-06-28 04:44:32 UTC |
| Profile Built | 2026-06-28 22:49:28 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 30 |
Full dossier details are available via our API.