# IP Intelligence Briefing: 116.203.187.155/32
## Executive Summary
IP address 116.203.187.155 is a web server hosting service operating on Hetzner Online GmbH infrastructure in Nuremberg, Germany. The IP carries a moderate risk score of 40 and serves the Greek domain aea.gr. While the IP demonstrates no active threat indicators in current assessments, the moderate risk classification warrants continued monitoring.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate) |
| **ASN** | 24940 (Hetzner Online GmbH) |
| **Organization** | Hetzner Online GmbH - Contact Role |
| **Location** | Nuremberg, Bavaria, Germany (DE) |
| **Network Range** | 116.203.0.0/16 |
| **Subnet Abuse Density** | 0 (mostly_clean) |
| **Infrastructure Type** | Web Server / Hosting |
## Service & DNS Analysis
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS)
- Web Server: nginx (EasyEngine 3.7.5)
- TLS Certificate: Let's Encrypt (R13), issued for aea.gr
- DNS PTR Record: static.155.187.203.116.clients.your-server.de
- SPF/DMARC: SPF record configured for aea.gr; DMARC status pending validation
## Threat Intelligence
- Blacklist Status: No confirmed blacklist hits in current assessment
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: No known campaign matches
- Control Plane: Route stable (0 route changes in 30 days), DNSSEC valid
## Temporal Analysis
- Observation Count: 21 historical signals recorded
- Threat Persistence: 0 days (not persistently malicious)
- Recent Activity: Consistent geolocation to Germany; provider identification stable
- Ownership Changes: 0 recorded
## Network Neighborhood Assessment
The /24 subnet (116.203.187.155/24) shows:
- Abuse Density: 0
- Classification: mostly_clean
- Threat Siblings: 1 detected
- Active Siblings: 1
- Overall: Subnet demonstrates low abuse activity
## Recommended Security Actions
Based on the IP's risk profile, the following blocking rules are recommended:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 116.203.187.155 -j DROP
# nftables
nft add rule inet filter input ip saddr 116.203.187.155 drop
```
WAF/CDN Blocking:
- Cloudflare WAF: Block IP with expression `ip.src eq 116.203.187.155`
- AWS WAF: Add address 116.203.187.155/32 to block list
## Intelligence Notes
The moderate risk score (40) stems from hosting infrastructure classification rather than active malicious behavior. The IP serves legitimate hosting functions for the Greek domain aea.gr. However, the presence of one threat sibling in the subnet suggests potential related activity that warrants awareness. No immediate malicious indicators were observed during the assessment period.
Recommended SOC Action: Monitor for any changes in reputation score or the emergence of threat indicators. Current risk level does not warrant immediate takedown but should be included in routine threat monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.155.187.203.116.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.155.187.203.116.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | aea.grwww.aea.gr |
| Valid From | 2026-04-05T22:34:10+00:00 |
| Valid Until | 2026-07-04T22:34:09+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 0692A056FD784BAA44956808C75CD7634CA4 |
| Thumbprint | 513EB5354C66C38322468FD9782FF2D138BD195A |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 21:26:55 UTC |
| Last Seen | 2026-06-28 07:47:04 UTC |
| Profile Built | 2026-06-29 01:51:50 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.