IP Intelligence Briefing: 128.140.110.145
Date: 2026-06-08
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Provider: Hetzner Online GmbH (ARIN-regulated)
- Geolocation:
- Country: Germany (DE)
- City: Tabriz (Iran) [Likely data inconsistency; verify]
- Coordinates: 51.17°N, 10.45°E
- Network Role:
- Cloud Compute instance (Hetzner)
- Hosting provider: Hetzner Online GmbH
- No CDN, VPN, or Tor association
---
**2. Threat Indicators**
- No malicious activity detected:
- No indicators of compromise (IOCs), spam, or known attacker campaigns.
- No DNS-based threats or malicious domain associations.
- DNS Configuration:
- PTR record: `static.145.110.140.128.clients.your-server.de`
- Domain: `your-server.de` (legitimate, but no additional security validation provided).
---
**3. Observation History**
- Single observation (June 8, 2026):
- Confirmed as a cloud-hosted server with no suspicious services or routing anomalies.
- No historical trends or persistent threats.
---
**4. Relationships**
- DNS Associations:
- Linked to `static.145.110.140.128.clients.your-server.de` (repeatedly observed).
- Network Relationships:
- Subnet: `128.140.110.145/24` (no active or malicious sibling IPs).
- Associated with network `CLOUD-NBG1` (likely Hetznerβs internal network label).
---
**5. Neighborhood Analysis**
- Subnet Abuse Density: 0% (clean).
- No neighboring IPs in the /24 subnet (likely a single-host allocation).
---
**6. Security Recommendations**
- Firewall Actions:
- Block the IP using:
- `iptables -A INPUT -s 128.140.110.145 -j DROP`
- `nft add rule inet filter input ip saddr 128.140.110.145 drop`
- Cloudflare/WAF/AWS WAF rules provided in tool response.
- Monitoring:
- Verify geolocation accuracy (Tabriz, Iran vs. Germany).
- Monitor for unexpected DNS changes or service exposure.
---
**7. Summary**
This IP is a legitimate Hetzner cloud instance with no detected malicious activity. While the geolocation data contains a potential inconsistency, the IP shows no signs of compromise. SOC teams should confirm the serverβs legitimacy and ensure no unauthorized services are exposed. Use the provided firewall rules for blocking if further suspicion arises.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | static.145.110.140.128.clients.your-server.de |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | static.145.110.140.128.clients.your-server.de |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | nginx/1.28.3 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.2 |
π TLS Certificate
| SANs | mascotas-migue-api.duckdns.org |
| Valid From | 2026-05-21T21:27:55+00:00 |
| Valid Until | 2026-08-19T21:27:54+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 06EDC023B802F466DFDEB996E7DF6E9C6942 |
| Thumbprint | 17280CCA9F19B7CDFA84D80BB248889736C84BE7 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 21:39:05 UTC |
| Last Seen | 2026-06-28 09:34:08 UTC |
| Profile Built | 2026-06-29 03:40:04 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.