IP Address

161.97.182.206

IPv4 Public
FR FR
AS51167
Contabo GmbH
201 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
10/10 Threat
94% Confidence
201 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 5% Most Dangerous
FR
France Location
Contabo GmbH ASN 51167
201 Reports
Honeypot Data Source

Critical Alert

IP 161.97.182.206 is a critical-risk address assessed at a 10/10 threat level, confirmed with 94% confidence as an exploited host that has generated 201 abuse reports from automated honeypot sensors since May 2026. This French IP address, operating through Contabo GmbH's network (AS51167), is actively engaged in malware and exploit activity after apparently being compromised by threat actors who now control it remotely for malicious operations.

The report volume and activity frequency of 8/10 reflect sustained, aggressive behavior observed across multiple detection sensors over a concentrated timeframe in May 2026. All 20 most recent reports consistently classify the address as an exploited host, indicating automated systems have definitively identified this machine as a compromised platform rather than a purposely malicious infrastructure node. The high confidence score underscores that the detection signature matches known patterns of compromised systems being weaponized for external attacks.

An exploited host poses a dual risk in the threat landscape: the legitimate owner or organization remains unaware their infrastructure has been subverted, while the compromised system simultaneously launches attacks against other targets. This pattern frequently involves the deployment of botnet agents, scanning tools, or exploit payloads that leverage the trusted reputation of the hosting provider's network. The anonymity granted by operating through a third-party hosting provider complicates attribution and extends the window of opportunity for malicious activity before intervention.

Network defenders should implement immediate blocking at the perimeter firewall level and monitor inbound traffic patterns for connections originating from this address. Engaging the hosting provider's abuse desk with evidence of the compromise can contribute to takedown of the malicious process. Deploying rate-limiting on exposed authentication endpoints and applying signature-based intrusion detection rules will reduce exposure to the automated exploitation techniques typically orchestrated from compromised hosts. Proactive monitoring for related infrastructure reuse patterns using the same ASN operator may also reveal coordinated campaigns.

More threatening than 98% of monitored IPs

Threat Categories

Exploited Host 30

Technical Details

This IP belongs to a compromised system being used as an attack platform without the owner's knowledge.

Recommended Mitigations

Block the IP and consider notifying the hosting provider or system owner about the compromise.

Behavioral Analysis

Activity Pattern: Declining

Activity has decreased recently, suggesting remediation or threat actor migration.

First Observed 14. May 2026
Last Activity 25. May 2026
Recent (7 days) 0 incidents

Reputable Network

This IP is hosted on a network (ASN 51167) with generally good reputation. The ISP Contabo GmbH maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring the positive trend.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 8/10 High
Confidence Score 94% Verified

Confidence History

18. May 2026 - 25. May 2026
94% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%

Technical Details

Basic Information

IP Address
161.97.182.206
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class B

Geolocation

Country
FR FR
ASN
AS51167
ISP
Contabo GmbH

DNS Information

Reverse DNS
vmi3300117.contaboserver.net
PTR Record
Yes
Connection Type
Static

Statistics

Total Reports
201
First Reported
14 May 2026
Last Reported
25 May 2026, 03:36

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS51167
Contabo GmbH
FR FR

Network Threat Assessment

2/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

778
Total IPs Monitored
28,942
Total Reports
37.2
Reports per IP

Network Context

This IP address belongs to Contabo GmbH (AS51167), which manages 778 IP addresses in our monitoring system. Out of these, 28,942 have been reported for suspicious activities, resulting in a network-wide threat level of 2/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

98 %

Global Threat Ranking

This IP is more threatening than 98% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 199,716 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 201 avg: 23 ++

Network Comparison

Compared against 1,142 IPs in ASN 51167

Threat Level 10/10 network avg: 5.0 ++
Total Reports 201 network avg: 26 ++
Network Contabo GmbH has overall threat level 2/10

Geographic Comparison

Compared against 4,068 IPs in FR

Threat Level 10/10 country avg: 5.8 ++
Total Reports 201 country avg: 31 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,375 threat incidents tracked globally • Last 24h: 18,936 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,468 20.5%
  2. 02
    IN
    India IN
    29,136 15.5%
  3. 03
    CN
    China CN
    26,029 13.9%
  4. 04
    BR
    Brazil BR
    10,256 5.5%
  5. 05
    DE
    Germany DE
    7,144 3.8%
  6. 06
    SG
    Singapore SG
    6,476 3.5%
  7. 07
    ID
    Indonesia ID
    5,551 3%
  8. 08
    RU
    Russia RU
    4,703 2.5%
  9. 09
    PK
    Pakistan PK
    4,677 2.5%
  10. 10
    NL
    Netherlands NL
    4,358 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
8.6/10 Avg Threat
98% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "161.97.182.206",
    "threat_level": 10,
    "confidence_score": 94,
    "total_reports": 201,
    "country_code": "FR",
    "isp_name": "Contabo GmbH",
    "asn": "51167",
    "first_reported": "2026-05-14 20:34:42",
    "last_reported": "2026-05-25 03:36:22",
    "exported_at": "2026-06-09T10:46:55+02:00",
    "source": "https://reportedip.de/ip/161.97.182.206/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.