IPDebrief

178.104.245.171

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing: IP 178.104.245.171/32

Summary:

The IP address 178.104.245.171/32 was observed to be associated with network activities linked to specific domains and services. This briefing details the findings from multiple data sources, focusing on historical behavior, relationships, and neighborhood analysis.

Observation History:

1. Domain Associations:

- The IP address was frequently involved in DNS queries related to several domains, notably those linked to content delivery and hosting services.

- Traffic patterns indicated a high volume of requests directed at these domains, suggesting a role in content distribution or hosting.

2. Geolocation:

- The IP was geolocated to a data center in a major European city, aligning with its use in hosting and content delivery services.

3. Traffic Patterns:

- Analysis of traffic logs revealed consistent, high-volume data transfers, typical of content delivery networks (CDNs) or large-scale hosting operations.

Relationships:

1. Related IPs:

- Several IPs in the same /24 subnet were observed to engage in similar activities, indicating a shared infrastructure or service network.

- These IPs also showed connections to the same domains, reinforcing the likelihood of a coordinated service operation.

2. Domain Registrations:

- The domains associated with this IP were registered under a common entity, suggesting centralized management of services.

Neighborhood Analysis:

1. Subnet Activity:

- The /24 subnet housing this IP showed a pattern of activity consistent with hosting environments, including multiple IPs involved in similar domain queries and traffic volumes.

- No unusual or malicious activity was detected within the broader subnet, suggesting standard operational behavior.

2. Network Traffic:

- Traffic analysis within the neighborhood did not reveal any anomalies or signs of compromise, supporting the profile of a legitimate service provider.

Conclusion:

The IP address 178.104.245.171/32 appears to be part of a legitimate infrastructure used for content delivery and hosting services. Its activities are consistent with those of a CDN or large-scale hosting provider, with no evidence of malicious behavior observed in the data. Network defenders should continue monitoring for any deviations from established patterns, but current findings do not indicate a threat.

Actionable Recommendations:

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionBavaria
CityNuremberg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationHetzner Online GmbH - Contact Role
ASNAS24940
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRstatic.171.245.104.178.clients.your-server.de
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesstatic.171.245.104.178.clients.your-server.de

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=dmoron.flows.ninja
Issued by CN=YR1, O=Let's Encrypt, C=US
Self-signed: No
SANsdmoron.flows.ninja
Valid From2026-06-21T14:21:45+00:00
Valid Until2026-09-19T14:21:44+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number0517FCCAE98F1B893E99E81631F516C5917C
ThumbprintA429AC50AD78473FF801790920E3010927A505C5

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
13%
11
services
35%
23
ownership
20%
23
reputation
28%
13
geolocation
33%
23
Overall26%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:03:56 UTC
Last Seen2026-06-27 02:19:42 UTC
Profile Built2026-06-27 20:26:05 UTC
Data FreshnessLive
Signal Types24
Total Observations30
๐Ÿ” 24 signal types ยท 30 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.