IP INTELLIGENCE BRIEFING
Target: 167.233.21.238/32
Classification: LOW RISK - Cloud Infrastructure
Date: 2026-06-16
---
EXECUTIVE SUMMARY
IP address 167.233.21.238 is a low-risk Hetzner cloud infrastructure endpoint with minimal threat indicators. Risk score of 25 reflects standard cloud hosting activity with one DNSBL listing. No active malicious behavior detected.
---
IDENTITY & OWNERSHIP
- Organization: Hetzner Online GmbH (AS24940)
- Network Name: CLOUD-FSN1
- CIDR Block: 167.233.16.0/20
- Infrastructure Type: Cloud Compute Environment
- Registration: ARIN registry
GEOLOCATION
- Country: Germany (DE)
- City: Gunzenhausen, Bavaria
- Coordinates: 51.17°N, 10.45°E
- Geo Validation: Incongruent signal (geoPlausible: false)
---
THREAT INDICATORS
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Threat Classifications:
- Not a Tor exit node
- Not identified as known attacker
- Not identified as spam source
- Active Threats: None identified
- Known Campaigns: None
---
NETWORK SERVICES
- Open Ports: None detected (firewalled)
- DNS Resolution: static.238.21.233.167.clients.your-server.de
- Reverse DNS: Forward-confirmed
- HTTP/HTTPS Services: Not actively serving (firewalled)
---
TEMPORAL ANALYSIS
- Ownership Changes: 0 (stable)
- Threat Persistence Days: 0
- Threat Observation Count: 1
- Persistently Malicious: False
HISTORY SUMMARY
20 observations recorded over recent period. Signals indicate consistent low-risk profile with single threat observation. No escalation patterns detected.
---
RELATIONSHIP MAPPING
13 relationships identified:
- 7 Same Network associations (CLOUD-FSN1 subnet)
- 6 DNS hostname associations (your-server.de)
- No certificate matches
- No correlated IPs in known campaigns
---
NEIGHBORHOOD ANALYSIS
Subnet: 167.233.21.0/24
- Abuse Density: 1 (Low)
- Classification: mostly_clean
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 1
---
RECOMMENDED ACTIONS
Security Posture: Acceptable for standard traffic
Firewall Rules: None required
Monitoring Level: Standard
SOC Analyst Notes:
- Endpoint exhibits typical cloud hosting behavior
- Single DNSBL listing warrants standard monitoring
- No immediate blocking or alerting recommended
- Continue baseline observation
- Review DNSBL listing details if inbound traffic affected
---
CONFIDENCE LEVEL: MEDIUM
Data Freshness: Current (2026-06-16)
Analysis Method: Multi-source signal aggregation
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | CLOUD-FSN1 |
| CIDR Block | 167.233.16.0/20 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.238.21.233.167.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.238.21.233.167.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | โ |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | squid/3.3.8 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-06-13T19:33:36+00:00 |
| Valid Until | 2036-06-10T19:33:36+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
| Serial Number | 540400C7BF9FF8B9AB47C5EA81A077892780750C |
| Thumbprint | 0407F70FD406FA1E502F398CCC10154ACEC9C36C |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims PH but primary geo says DE
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-04 00:31:30 UTC |
| Last Seen | 2026-06-29 13:10:27 UTC |
| Profile Built | 2026-06-29 13:16:45 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 25 |
Full dossier details are available via our API.