# IP Intelligence Briefing: 178.104.243.214
## Executive Summary
The IP address 178.104.243.214 is a static cloud compute instance hosted by Hetzner Online GmbH in Nuremberg, Germany. Current risk assessment classifies the IP as low risk, though recent blacklist activity warrants monitoring. The address is associated with your-server.de infrastructure and maintains standard security configurations.
## Ownership and Network Classification
- ASN: 24940 (Hetzner Online GmbH)
- Infrastructure Type: Cloud Compute
- Organization: Hetzner Online GmbH
- CIDR Block: 178.104.243.0/24
- BGP Prefix: 178.104.0.0/15
- Route Stability: Unstable (route changes detected)
- Operator Score: 0.3478 (Basic)
## Geolocation and Routing
- Country: Germany (DE)
- Region: Bavaria
- City: Nuremberg
- Coordinates: 51.17°N, 10.45°E
- Timezone: Europe/Berlin
- Minimum RTT: 108ms
- Average RTT: 111.2ms
## DNS and Email Configuration
- PTR Hostname: static.214.243.104.178.clients.your-server.de
- Forward Resolution: Confirmed
- Domain: your-server.de
- SPF Record: Present
- DMARC Record: Present
- CAA Records: Present
- DNSSEC: Valid
- Open Ports: None detected (firewalled/no services)
## Threat Indicators
- Risk Score: 0
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
## Control Plane Analysis
- DNSBL Listed: 0 (of 8 total lists scanned)
- RPKI State: Not assessed
- IRR Consistency: Not assessed
- Route Changes (30d): 0
- DNSSEC Valid: Yes
## Historical Observation Summary
Total Observations: 22
Recent Activity Timeline:
- 2026-06-19: Listed on 8 threat feeds with maximum severity rated as "high" (confidence: 0.85)
- 2026-06-17: Minimal signal activity (operator score: 0.2174)
- 2026-06-14: Geolocation confirmed for Germany
Risk Trend: Recent escalation in blacklist activity detected on June 19, 2026, despite historically low-risk profile.
## Network Neighborhood Assessment
- Subnet: 178.104.243.214/24
- Abuse Density: 0 (clean)
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 1
- Classification: Mostly clean
- Inherited Risk: 2
## Relationship Graph
- DNS Associations: static.214.243.104.178.clients.your-server.de (multiple entries)
- Network Associations: CLOUD-NBG1 (Hetzner datacenter)
- Total Relationships: 44
## Recommended Security Actions
Based on current risk profile (low risk, 0/100 score):
- No immediate blocking recommended
- Monitor for continued blacklist activity
- Verify recent high-severity listings if traffic observed from this IP
- Standard logging and monitoring maintained
## Intelligence Assessment
The IP 178.104.243.214 represents a standard Hetzner cloud hosting infrastructure instance. While the current risk score indicates low threat activity, the recent blacklist entries from June 19, 2026, suggest the address may have been associated with malicious activity at that time. The address maintains proper email authentication (SPF, DMARC) and DNSSEC validation. No open services or ports were detected, indicating the instance is either firewalled or not actively hosting services. The subnet environment shows minimal abuse density with one identified threat sibling. SOC teams should monitor for recurrence of the blacklist activity while maintaining standard defensive posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.214.243.104.178.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.214.243.104.178.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:56 UTC |
| Last Seen | 2026-06-27 02:19:32 UTC |
| Profile Built | 2026-06-27 20:26:05 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.