IP Intelligence Briefing: 176.9.145.139
Date: 2026-06-11
---
**1. Risk Profile**
- Overall Risk: Low (Risk Score: 25/100)
- Provider Score: 0 (Hetzner Online GmbH)
- Authority Score: 0
- Stability: Stable (no recent ownership or threat persistence changes)
---
**2. Ownership & Geolocation**
- ISP: Hetzner Online GmbH (AS24940)
- Location: Falkenstein, Saxony, Germany (51.17°N, 10.45°E)
- Network: Subnet `176.9.145.128/27` (clean, no abuse density)
- Infrastructure: CloudCompute (likely a dedicated server or virtualized instance)
---
**3. Network & Service Configuration**
- Open Ports:
- TCP 80 (HTTP), TCP 443 (HTTPS)
- TLS Certificate:
- Issuer: *Sectigo Public Server Authentication CA DV R36*
- Subject: **.blog-dog.de
- Validity: Not specified (likely current)
- Server Fingerprint:
- Web Server: `nginx/1.18.0 (Ubuntu)`
- HTTP/2 Enabled, HSTS, and CSP headers detected.
- DNS:
- PTR record: `static.139.145.9.176.clients.your-server.de`
- No malicious domain or email auth anomalies.
---
**4. Threat & Abuse Indicators**
- Threat Status: Clean (no malware, spam, or attacker indicators)
- DNSBL: Listed in 1 of 8 DNSBLs (low priority)
- Historical Activity:
- Recent TLS scans (June 11, 2026) show no vulnerabilities.
- No observed phishing, C2, or scan activity.
---
**5. Neighborhood Analysis**
- Subnet: `176.9.145.139/24`
- Neighbors: 0 active IPs (isolated host)
- Abuse Density: 0% (subnet is clean)
---
**6. Recommendations**
- Monitor: Track TLS certificate expiration and HTTP/2 compliance.
- Firewall: Allow traffic on ports 80/443 if required; consider rate-limiting to mitigate DDoS risks.
- Verify: Confirm ownership with Hetzner to ensure no unauthorized access.
Conclusion: This IP is a low-risk cloud-hosted server with no malicious activity detected. No immediate defensive action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | HETZNER-fsn1-dc7 |
| CIDR Block | 176.9.145.128/27 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.139.145.9.176.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.139.145.9.176.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.18.0 (Ubuntu) |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | *.blog-dog.deblog-dog.de |
| Valid From | 2025-12-18T00:00:00+00:00 |
| Valid Until | 2026-12-18T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 00983019837D522F65D4F3FCDDCEB8960D |
| Thumbprint | 1617E7F71FE3F3E83CB82E2FF4F5FB5F1F441D70 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-26 18:57:10 UTC |
| Last Seen | 2026-06-29 03:17:03 UTC |
| Profile Built | 2026-06-29 09:20:56 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.