# IP Intelligence Briefing: 89.117.53.97/32
Classification: Low Risk | Risk Score: 25 | Generated: [Current Date]
## Executive Summary
IP address 89.117.53.97 is classified as low-risk with a score of 25. The IP is hosted on Contabo infrastructure (ASN 51167) in Lithuania and operates as a single-service host with SSH service accessible. No active threat indicators or malicious campaigns have been identified.
## Infrastructure Profile
Network Assignment:
- ASN: 51167 (LRTC-MNT)
- Organization: LRTC-MNT
- RIR: RIPE
- CIDR Block: 89.117.48.0/20
- Network Role: Single-Service Host (Cloud Compute)
- Provider: Contabo
Geolocation:
- Country: Lithuania (LT)
- Region: Grand Est
- City: Lauterbourg
- Timezone: Europe/Lithuania
DNS Resolution:
- PTR Record: vmi2901078.contaboserver.net
- Forward Resolution: vmi2901078.contaboserver.net (confirmed)
- Hosted Domain Count: 0
## Active Services
| Port | Protocol | Service | Banner |
|---|---|---|---|
| 22 | TCP | SSH | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
No TLS certificate, HTTP content, or web services detected.
## Threat Assessment
Current Risk Indicators:
- Abuse Confidence Score: Not applicable (no active threats)
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
DNSBL Status: Listed on 1 of 8 DNSBL lists
Risk Breakdown:
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Overall Classification: Low Risk
## Neighborhood Analysis
Subnet: 89.117.53.97/24
- Abuse Density: 0 (Clean)
- Inherited Risk: 0
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
No elevated risk observed within the immediate /24 subnet.
## Observation History
Total Observations: 21 signals
Recent Observations:
- 2026-06-28T01:36:44: Cloud compute infrastructure identified; provider confirmed as Contabo
- 2026-06-19T23:32:56: Provider confirmed as Contabo; network classification maintained
- 2026-06-19T23:30:51: Operator score 0.2609 (Basic); subnet classification clean
Temporal Indicators:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 1
- Persistently Malicious: No
## Relationship Graph
Total Relationships: 45
- Same Network Relationships: Multiple entries pointing to LRTC_INETNUM_RENT network identifiers
- External Hostnames/Organizations: None identified
- Certificates: None
## Recommended Actions
Risk-Based Recommendations:
- No immediate blocking or firewall rules recommended
- Standard monitoring practices apply
- Risk score of 25 indicates low threat level
Firewall Considerations:
- SSH port 22 is open; evaluate based on organizational policy
- No evidence of malicious activity requiring immediate remediation
Monitoring Priorities:
- Track for any changes in threat indicators
- Monitor for DNSBL additions
- Observe for changes in network classification
## Intelligence Assessment
The IP address 89.117.53.97 presents a low-risk profile consistent with legitimate Contabo hosting infrastructure. The clean subnet classification, absence of threat indicators, and stable ownership history suggest this is not a malicious actor IP. No immediate defensive action is required beyond standard operational monitoring.
Confidence Level: High
Data Freshness: Current (within last 7 days)
Threat Status: Active monitoring recommended but no immediate action required
---
*This briefing is based on IPDebrief intelligence data and should be correlated with additional threat intelligence sources before operational decisions.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | LRTC-MNT |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi2901078.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi2901078.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 8% | 1 | 1 |
| Overall | 18% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 19:29:55 UTC |
| Last Seen | 2026-06-28 01:36:40 UTC |
| Profile Built | 2026-06-29 01:46:05 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.