IPDebrief

178.104.254.183

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 178.104.254.183

## Executive Summary

IP address 178.104.254.183 is a low-risk residential/hosting IP registered to Hetzner Online GmbH, operating from Nuremberg, Bavaria, Germany. The IP demonstrates stable infrastructure characteristics with minimal threat indicators, though moderate operator-level risk factors warrant routine monitoring.

## Infrastructure Profile

AttributeValue
**Risk Score**25 (Low Risk)
**ASN**24940 (Hetzner Online GmbH)
**Organization**Hetzner Online GmbH - Contact Role
**Country/Region**Germany / Bavaria
**City**Nuremberg
**Infrastructure Type**Cloud Compute / Hosting
**Network Classification**Cloud / Hosting Provider
**Stability**Route stable (0 changes in 30 days)
**DNSSEC**Valid
**IRR Consistency**Match

## Technical Fingerprint

- PTR: static.183.254.104.178.clients.your-server.de

- Forward Resolution: Confirmed

- SPF: Present

- DMARC: Present

## Threat Indicators

IndicatorStatus
Known AttackerNo
Spam SourceNo
Tor Exit NodeNo
Blacklist Count0
Abuse Confidence ScoreNot assigned
Known CampaignsNone
Threat FeedsNone
DNSBL Listings1 of 8 lists

## Control Plane Analysis

## Neighborhood Assessment

## Observation History (30 signals)

Recent observations indicate:

## Relationships

## Recommended Actions

Based on the low-risk profile and minimal threat indicators, the following actions are recommended:

1. Allow: Standard web traffic (ports 80, 443) with rate limiting

2. Monitor: SSH access (port 22) if inbound traffic observed

3. Block: No immediate blocking required

4. Monitor List: Add to watchlist for operator-level scoring changes

## Intelligence Narrative

The IP address 178.104.254.183 operates as a legitimate cloud hosting service under Hetzner's infrastructure. The moderate operator score (0.7391) and single DNSBL listing suggest the IP may have been involved in minor abuse activities historically, though current indicators show no active malicious behavior. The infrastructure demonstrates stability with consistent routing and valid DNSSEC. The historical anomaly (UK geolocation signal vs. German registration) appears to be a geolocation discrepancy rather than evidence of malicious activity.

Classification: LOW RISK โ€” Continue routine monitoring

Priority: Standard

Action: Allow with standard web filtering policies

---

*Data Source: IPDebrief Intelligence Platform*

*Analysis Date: Based on latest available signal observations*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionBavaria
CityNuremberg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationHetzner Online GmbH - Contact Role
ASNAS24940
Network Nameโ€”
CIDR Block178.104.0.0/15
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRstatic.183.254.104.178.clients.your-server.de
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesstatic.183.254.104.178.clients.your-server.de

๐Ÿ” DNS Hygiene

Hygiene Score100% (Excellent)
SPF2/2 domains
DMARC2/2 domains
FCrDNSVerified
DNSSECValid
CAAPresent
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.18.0 (Ubuntu)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=app.mps.rs
Issued by CN=R12, O=Let's Encrypt, C=US
Self-signed: No
SANsapp.mps.rs
Valid From2026-05-24T02:06:07+00:00
Valid Until2026-08-22T02:06:06+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number05AB69535D8817EF08198E935A4EAEFC9154
Thumbprint27CFF0782756425810567170CFE856DA4812FA50

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
22%
34
services
30%
23
ownership
27%
34
reputation
26%
13
geolocation
39%
23
Overall28%1321
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionHigh (85%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-20 05:43:54 UTC
Last Seen2026-06-28 10:51:27 UTC
Profile Built2026-06-29 04:57:04 UTC
Data FreshnessLive
Signal Types30
Total Observations35
๐Ÿ” 30 signal types ยท 35 observations collected
This report is generated from 30+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.