# IP Intelligence Briefing: 167.233.163.237/32
## Executive Summary
IP address 167.233.163.237 operates within Hetzner Online GmbH's cloud infrastructure (ASN 24940, CLOUD-NBG1, 167.233.160.0/20) in Germany. The IP carries a moderate risk score of 50 and appears on 2 of 8 DNSBL listings. The address resolves to your-server.de hostnames and exposes HTTP and SSH services on nginx infrastructure. Neighborhood analysis indicates the /24 subnet is classified as clean with zero abuse density.
## Ownership and Infrastructure
| Attribute | Value |
|---|---|
| **Organization** | Hetzner Online GmbH - Contact Role |
| **ASN** | 24940 |
| **CIDR Block** | 167.233.160.0/20 |
| **Infrastructure Type** | CloudCompute |
| **Country** | DE (Germany) |
| **Service Purpose** | Multi-Service Host |
## Network Classification
- Is Cloud: Yes
- Is Hosting: Yes
- Is CDN: No
- Is VPN/Proxy/Tor: No
- Is Mobile/Residential: No
- DNS Resolution: Forward confirmed to static.237.163.233.167.clients.your-server.de
- Server Banner: nginx
- HTTP Version: 1.1
## Threat Indicators
- Abuse Confidence Score: Not reported
- Blacklist Count: 0 (DNSBL listed on 2 of 8 lists)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Associations: None identified
## Services Exposure
- Port 80/TCP: HTTP (nginx)
- Port 22/TCP: SSH (OpenSSH 10.2p1 Ubuntu-2ubuntu3.5)
## Observation History
Analysis of 26 historical observations indicates stable infrastructure characteristics. Recent signals (August 2026) confirm:
- Consistent geolocation inference (Germany, coordinates: 51.17°N, 10.45°E)
- Persistent DNS resolution to your-server.de
- Stable HTTP response patterns (200 OK, ~460ms TTFB)
- No changes in network classification (Hetzner cloud infrastructure)
## Neighborhood Analysis
Subnet 167.233.163.237/24 exhibits the following characteristics:
- Abuse Density: 0%
- Threat Siblings: 0
- Active Siblings: 1
- Classification: Clean
## Security Recommendations
The actions engine generated the following rules based on risk score 50. These are probabilistic and should be validated against additional threat signals:
```bash
# iptables
iptables -A INPUT -s 167.233.163.237 -j DROP
# nftables
nft add rule inet filter input ip saddr 167.233.163.237 drop
# nginx
deny 167.233.163.237;
# Cloudflare WAF
ip.src eq 167.233.163.237 โ BLOCK
# AWS WAF
Addresses: ["167.233.163.237/32"]
```
## Assessment
This IP represents a cloud-hosted infrastructure endpoint under Hetzner's CLOUD-NBG1 network. While the risk score of 50 triggers defensive rule generation, the subnet shows no abuse indicators and the IP is not associated with known threat campaigns or malicious infrastructure. The DNSBL presence warrants monitoring but does not indicate active threat activity. SOC analysts should prioritize validation before implementing blocking rules, considering the IP's legitimate cloud hosting context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | CLOUD-NBG1 |
| CIDR Block | 167.233.160.0/20 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.237.163.233.167.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.237.163.233.167.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 09:12:01 UTC |
| Last Seen | 2026-08-13 06:44:03 UTC |
| Profile Built | 2026-08-12 20:31:57 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 27 |
Full dossier details are available via our API.