Your IP: 216.73.216.123
๐ค Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.
IP Intelligence Briefing: 94.72.126.37
Date: 2026-06-16
---
**1. Risk Profile**
- Overall Risk: Moderate (Risk Score: 50)
- Threat Indicators: Listed in 8 threat feeds (high severity) on multiple dates (June 10โ15, 2026).
- Network Classification: Hosted on Contabo cloud infrastructure (ASN: 40021).
---
**2. Geolocation & Ownership**
- Location: Registered to Germany (DE) but geolocated to Seattle, Washington (latitude: 51.17, longitude: 10.45).
- Owner: Johannes Selg (RIPE RIR, ASN 40021).
- Abuse Contact: Available via RDAP.
---
**3. Network Context**
- Subnet: 94.72.126.37/24 (abuse density: 1, classified as "mostly_clean").
- Hosting Role: CloudCompute instance (no residential/mobile traffic).
- DNS Associations: Linked to `vmi2783207.contaboserver.net` (multiple DNS records).
---
**4. Threat Observations**
- Recent Activity:
- Listed in 8 threat feeds (June 10โ15, 2026) with high severity.
- No active neighbors in the /24 subnet (0 threat siblings).
- Behavioral Flags: No open ports, no TLS certs, no HTTP services detected.
---
**5. Recommendations**
- Monitor: Track listings in threat feeds (e.g., DNSBLs, IP reputation services).
- Investigate: Verify geolocation discrepancy (Germany vs. Seattle).
- Network Segmentation: Isolate cloud-hosted assets to limit lateral movement risks.
- DNS Analysis: Validate `vmi2783207.contaboserver.net` for potential C2 or command-and-control activity.
---
Source: IPDebrief Threat Intelligence Platform
Note: No immediate mitigation actions required, but ongoing monitoring is advised due to recent threat feed listings.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS40021 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi2783207.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi2783207.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
No certificate
Issued by โ
N/A
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 26% | 2 | 2 |
| Overall | 20% | 9 | 13 |
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 18:42:03 UTC |
| Last Seen | 2026-06-29 00:43:19 UTC |
| Profile Built | 2026-06-29 06:46:06 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
๐ 19 signal types ยท 21 observations collected
This report is generated from 19+ independent intelligence signals including
ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds,
behavioral fingerprinting, and more.
Full dossier details are available via our API.
Full dossier details are available via our API.
โน๏ธ About This Report
All data shown is publicly available network metadata โ IP addresses do not reliably identify individuals.
Assessments are probabilistic and should not be used as sole basis for access control decisions.
To report an issue or request data review, contact admin@ipdebrief.com.