# INTELLIGENCE BRIEFING: IP 116.202.210.109
## Executive Summary
IP 116.202.210.109 presents as a low-risk (score: 25) cloud computing endpoint hosted by Hetzner Online GmbH in Falkenstein, Saxony, Germany. The address operates standard web infrastructure with no active threat indicators.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **ASN** | 24940 (Hetzner Online GmbH) |
| **Geolocation** | Germany (DE), Saxony, Falkenstein |
| **Infrastructure** | CloudCompute / Hosting |
| **Classification** | Cloud Provider Environment |
| **Network Range** | 116.202.0.0/16 (BGP Prefix) |
## Threat Assessment
- Overall Risk: Low (Score: 25)
- Known Campaigns: None detected
- Blacklist Status: 0 blacklists; 1 DNSBL listing
- Tor/Proxy/VPN: No indicators of abuse infrastructure
- Is Known Attacker: False
- Is Spam Source: False
## Technical Services
- Open Ports: 80/HTTP, 443/HTTPS, 22/SSH
- Web Server: nginx/1.24.0 (Ubuntu)
- TLS Certificate: Let's Encrypt (CN=alloemmanuals.com)
- DNS Records: Reverse DNS confirmed (static.109.210.202.116.clients.your-server.de)
- Email Authentication: SPF and DMARC records present
## Behavioral History (24 Observations)
Temporal analysis reveals consistent cloud hosting classification across the observation period. Recent observations (June 2026) confirm:
- Stable infrastructure type (CloudCompute)
- Geographic validation: 454.2km from claimed location with 122ms average RTT
- HTTP headers indicate Content Security Policy and HSTS enabled
- No ownership or threat persistence changes observed
## Network Relationships
- DNS Associations: Multiple hostname associations to your-server.de infrastructure
- Network Relationships: DE-HETZNER-2010117 network designation
- Total Relationships: 39 entities linked
## Neighborhood Analysis (116.202.210.0/24)
- Abuse Density: 0
- Classification: Mostly clean
- Risk Distribution: No high or medium-risk siblings
- Threat Siblings: 0
## Recommended Actions
Based on the low-risk profile and legitimate cloud hosting classification:
- No blocking recommended for general traffic
- Monitor: Standard logging for SSH port 22 activity
- Allow: Normal HTTP/HTTPS traffic patterns
## Intelligence Conclusion
This IP address represents a legitimate cloud hosting environment operating standard web services. No malicious activity, threat campaigns, or anomalous behavior detected. The address maintains consistent infrastructure characteristics and exhibits no indicators of abuse. Routine monitoring appropriate; no defensive restrictions required.
*Report generated from IPDebrief intelligence data. Last updated: 2026-06-28*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.109.210.202.116.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.109.210.202.116.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | alloemmanuals.comwww.alloemmanuals.com |
| Valid From | 2026-05-20T02:57:05+00:00 |
| Valid Until | 2026-08-18T02:57:04+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 06950963D25D52CB15DFCD8D8C93CD51E0D6 |
| Thumbprint | 486FB2DDA96C4640441FDB6DBDDFCE5975D4D335 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 15:37:37 UTC |
| Last Seen | 2026-06-28 08:58:17 UTC |
| Profile Built | 2026-06-29 03:03:41 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.