IPDebrief

94.72.127.251

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 94.72.127.251/32

## Executive Summary

IP address 94.72.127.251/32 presents a low-risk profile (score: 25) with mixed operational indicators. The IP is registered to Contabo (ASN 40021) and operates as a cloud compute host in the German network 94.72.120.0/21. However, geolocation inconsistencies and DNSBL listings warrant continued monitoring. The subnet classification is "mostly_clean" with low abuse density.

## Network Classification

AttributeValue
ProviderContabo
Infrastructure TypeCloud Compute
ASN40021 (Johannes Selg)
CIDR Block94.72.120.0/21
BGP Prefix94.72.120.0/21
Route StabilityUnstable (route changes observed)
RPKI StateNot Validated
DNSSECValid
Is CloudYes
Is HostingYes

## Geolocation Analysis

Current Consensus: Germany (DE), Swidnik, Region 06

Coordinates: 51.17°N, 10.45°E

Timezone: Europe/Berlin

Anomaly Detected: Geolocation validation failed with RTT violation. Minimum observed RTT (79.0ms) is below the theoretical minimum (158.2ms) for the stated distance (7,910km), indicating potential geolocation spoofing or routing irregularities.

## Observations and History

The IP has generated 22 signal observations. Key temporal patterns:

June 28, 2026:

June 20, 2026:

Geographic Inconsistency: The IP has been observed across Germany, Poland, and United States within a 7-day window, indicating either aggressive spoofing or legitimate multi-region cloud operations.

## DNS and Service Analysis

FieldValue
PTR Hostnamevmi3195040.contaboserver.net
Forward ResolutionConfirmed
Open PortsTCP/22 (SSH-2.0-OpenSSH_8.9p1 Ubuntu)
Hosted Domains0
Email AuthSPF: No, DMARC: No

Service Fingerprint: Standard cloud server with SSH access. No web services, TLS certificates, or HTTP headers detected.

## Threat Indicators

## Network Neighborhood

AttributeValue
Subnet94.72.127.251/24
Abuse Density1 (Low)
Classificationmostly_clean
Total Siblings1
Active Siblings0
Threat Siblings1

No significant neighboring IPs detected within the /24 subnet.

## Relationship Graph

37 relationships identified:

## Recommended Actions

PriorityAction
LowMonitor for geographic instability
LowAdd to watchlist due to DNSBL presence
NoneNo immediate blocking required

## Intelligence Assessment

This IP address represents a standard Contabo cloud hosting environment with one DNSBL listing. The primary concern is the geographic inconsistency observed between June 20-28, 2026, which could indicate either:

1. Legitimate multi-region cloud operations

2. Aggressive IP reputation manipulation

3. Routing anomalies unrelated to abuse

The low abuse density in the surrounding subnet and lack of active threat siblings suggest minimal immediate threat. However, the RTT/geolocation violation and transient threat signals warrant periodic re-evaluation.

Confidence Level: Medium

Recommended Action: Monitor

---

*Report generated: 2026-06-28 | Data sources: IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
Region06
CitySwidnik
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationJohannes Selg
ASNAS40021
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvmi3195040.contaboserver.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvmi3195040.contaboserver.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
24
routing
8%
11
services
15%
22
ownership
20%
23
reputation
28%
13
geolocation
39%
23
Overall24%1016
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-17 09:11:55 UTC
Last Seen2026-06-28 05:02:00 UTC
Profile Built2026-06-28 23:07:16 UTC
Data FreshnessLive
Signal Types23
Total Observations27
๐Ÿ” 23 signal types ยท 27 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.