IP INTELLIGENCE BRIEFING
Target: 178.104.75.140
Date: 2026-08-11
Classification: Moderate Risk
---
Executive Summary
The target IP (178.104.75.140) is a cloud hosting infrastructure endpoint operated by Hetzner Online GmbH (ASN 24940) in Nuremberg, Germany. The IP presents moderate risk (score: 50) with no active malicious indicators, but shows evidence of blacklist association and is hosted on Hetzner's CLOUD-NBG1 network segment.
---
Infrastructure Profile
- Organization: Hetzner Online GmbH - Contact Role
- Network: CLOUD-NBG1 (178.104.64.0/20)
- AS Number: 24940 (RIR: RIPE)
- Geolocation: Nuremberg, Bavaria, Germany (51.17°N, 10.45°E)
- Infrastructure Type: CloudCompute / Hosting Provider
- Service Status: No open services detected; connection appears firewalled
DNS Associations
- Primary hostname: static.140.75.104.178.clients.your-server.de
- Domain: your-server.de
- Email authentication: SPF and DMARC records present (SPF: ?all, DMARC: p=none)
- DNSSEC: Valid
---
Threat Assessment
- Risk Score: 50 (Moderate)
- Blacklist Status: Listed on 1 DNSBL (out of 8 total lists checked)
- Known Threat Indicators: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: None identified
- Abuse Confidence Score: Not applicable
Observed Behavior:
- No open ports or running services detected
- HTTP redirect (301) with nginx/1.24.0 server signature
- Control plane shows 1 DNSBL listing, route stability issues flagged
- Operator score: 0.3478 (Basic)
---
Neighborhood Analysis
Subnet 178.104.75.0/24 shows clean classification with:
- Abuse Density: 0
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 0
- Neighbor 178.104.75.129: Risk Score 0, Authority Score 60
The /24 subnet exhibits low abuse activity with no correlated malicious neighbors.
---
Historical Observations
Total signal observations: 23
- Recent activity includes multiple blacklist listings (max severity: high)
- DNS and operator signals observed across multiple observation windows
- No persistent malicious behavior pattern identified
- Ownership changes: 0
- Threat persistence days: 0
- Is persistently malicious: False
---
Recommended Actions
- Monitoring: Continue monitoring due to moderate risk score and blacklist associations
- Allow/Block: No immediate block recommendation; IP is legitimate cloud infrastructure
- Context: This is a Hetzner cloud hosting endpoint; false positive risk for blocking is elevated
- Investigation: Verify if the IP appears in specific threat intelligence feeds or if the blacklist listings relate to the target organization
---
Conclusion
This IP represents legitimate cloud hosting infrastructure with moderate risk due to blacklist associations. No active threat indicators were detected. SOC teams should treat as low-priority if the IP appears in traffic logs, but verify context before taking blocking action to avoid disrupting legitimate services.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | CLOUD-NBG1 |
| CIDR Block | 178.104.64.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.140.75.104.178.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.140.75.104.178.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | nginx/1.24.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 14:26:04 UTC |
| Last Seen | 2026-08-13 06:44:09 UTC |
| Profile Built | 2026-08-12 23:50:29 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.