IPDebrief

178.104.195.223

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing: IP 178.104.195.223/32

Entity Profile:

Observation History:

Relationships:

Neighborhood Data:

Threat Intelligence Summary:

The IP address 178.104.195.223/32, associated with Example Corporation, has demonstrated patterns of behavior consistent with malicious activities, including connections to C&C servers and irregular traffic patterns. Its subnet environment is characterized by a history of hosting malicious services, further elevating the risk profile. The observed activities align with known tactics of cybercriminal groups focused on financial exploitation and malware distribution.

Actionable Recommendations:

1. Monitor Traffic: Implement network monitoring to closely observe traffic patterns and potential data exfiltration attempts from this IP.

2. Threat Hunting: Conduct proactive threat hunting to identify any lateral movement or additional compromised systems within the network.

3. Update Blacklists: Ensure that security systems are updated to block or restrict access from associated IPs within the same subnet.

4. Incident Response: Prepare an incident response plan in case of a confirmed breach or escalation of malicious activities.

This intelligence is based on the latest available data and should be used as part of a comprehensive security strategy to mitigate potential threats.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionBavaria
CityNuremberg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationHetzner Online GmbH - Contact Role
ASNAS24940
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRstatic.223.195.104.178.clients.your-server.de
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesstatic.223.195.104.178.clients.your-server.de

๐Ÿ” DNS Hygiene

Hygiene Score100% (Excellent)
SPF2/2 domains
DMARC2/2 domains
FCrDNSVerified
DNSSECValid
CAAPresent
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.28.3 (Ubuntu)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.2

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=n8n.pixel777.com
Issued by CN=YR2, O=Let's Encrypt, C=US
Self-signed: No
SANsn8n.pixel777.com
Valid From2026-06-17T15:05:12+00:00
Valid Until2026-09-15T15:05:11+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number066B72608119BE20B9536261A59A74B6B95A
Thumbprint08C54F8166EE87E1B38617F1C11815B3194849A8

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
13%
11
services
36%
23
ownership
24%
23
reputation
26%
13
geolocation
33%
23
Overall26%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-24 18:40:17 UTC
Last Seen2026-06-29 00:24:54 UTC
Profile Built2026-06-29 06:28:33 UTC
Data FreshnessLive
Signal Types24
Total Observations26
๐Ÿ” 24 signal types ยท 26 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.