IPDebrief

89.117.61.157

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

INTELLECTUAL PROPERTY THREAT INTELLIGENCE BRIEFING

Target: 89.117.61.157/32

Classification: LOW RISK / HOSTING INFRASTRUCTURE

Date: 2026-06-14

---

EXECUTIVE SUMMARY

IP address 89.117.61.157 operates as a cloud hosting service provided by Contabo (ASN: 51167) with an overall risk score of 15 (Low Risk). The endpoint hosts a web server with HTTPS termination but presents minimal active threat indicators. The IP maintains a stable reputation profile with 24 historical observations recorded over the analysis period.

TECHNICAL PROFILE

Infrastructure:

Service Configuration:

Geolocation Data:

THREAT INDICATORS

Active Threats: None detected

DNS/Reputation:

HISTORICAL OBSERVATION ANALYSIS

Analysis of 24 observations from 2026-06-14 reveals consistent infrastructure characteristics:

Temporal Indicators:

Domain Activity:

Infrastructure Consistency:

NETWORK RELATIONSHIPS

Connected Entities: 52 relationships identified

Subnet Analysis (89.117.61.157/24):

SECURITY RECOMMENDATIONS

For SOC Analysts:

1. Monitor, Do Not Block: Current risk profile (15/100) warrants monitoring rather than blocking

2. Verify Domain Legitimacy: The stasbelo.com domain requires verification due to DMARC misconfiguration

3. Geolocation Discrepancy: Investigate coordinate/country mismatch (LT vs Grand Est region)

4. DNSBL Monitoring: Track continued DNSBL listing status (1/8 lists)

Firewall Rules (if required):

CONCLUSION

IP 89.117.61.157 represents a low-risk cloud hosting endpoint with no active malicious indicators. The primary concerns relate to operational hygiene (missing DMARC, geolocation inconsistencies) rather than active threats. Recommended actions include continued monitoring and verification of associated domain infrastructure.

---

*Intel prepared by IPDebrief Intelligence Analysis Team*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐ŸŒ Lithuania
RegionGrand Est
CityLauterbourg
Timezoneโ€”
Latitude56.00
Longitude24.00

๐Ÿข Ownership & Registration

OrganizationLRTC-MNT
ASNAS51167
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvmi3133273.contaboserver.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvmi3133273.contaboserver.net

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPF1/2 domains
DMARC0/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Servernginx/1.24.0 (Ubuntu)
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=ads.stasbelo.com
Issued by CN=E8, O=Let's Encrypt, C=US
Self-signed: No
SANsads.stasbelo.com
Valid From2026-05-26T11:15:05+00:00
Valid Until2026-08-24T11:15:04+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number0571E6944946D7E5D0CA0770FC13F1C2FF8D
ThumbprintEFF60935EECCE3CDEC69C470A84E3A8218C9BA65

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
15%
22
services
28%
24
ownership
17%
23
reputation
27%
13
geolocation
13%
11
Overall21%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionHigh (85%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-10 16:14:52 UTC
Last Seen2026-06-27 18:12:03 UTC
Profile Built2026-06-28 12:16:03 UTC
Data FreshnessLive
Signal Types22
Total Observations30
๐Ÿ” 22 signal types ยท 30 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.