# IP INTELLIGENCE BRIEFING
IP Address: 178.105.4.71/32
Classification: Low Risk / Cloud Infrastructure
Date: Current
## Executive Summary
The IP address 178.105.4.71 is a low-risk cloud hosting endpoint operating from Hetzner Online GmbH infrastructure in Falkenstein, Germany. The system demonstrates stable network characteristics with no active threat indicators, minimal abuse history, and a clean reputation profile.
## Network Profile
Risk Score: 25/100 (Low Risk)
Provider: Hetzner Online GmbH (ASN: 24940)
Infrastructure Type: Cloud Compute / Web Server
Geolocation: Falkenstein, Saxony, Germany (51.17°N, 10.45°E)
Registration: RIPE NCC, Europe
Network Role: The IP is classified as cloud hosting infrastructure with a stable provider footprint. The system operates within Hetzner's CLOUD-FSN1 network block (178.104.0.0/15).
## Service Exposure
Open Ports:
- Port 443/TCP (HTTPS) - nginx server
- Port 22/TCP (SSH) - OpenSSH_8.9p1 Ubuntu-3ubuntu0.15
- Port 8443/TCP (HTTPS-alt)
TLS Certificate:
- Issuer: CN=lab02.intalio.pl, OU=Zimbra Collaboration Server, O=CA
- Subject: CN=lab02.intalio.pl
- Certificate Type: Non-self-signed
DNS Configuration:
- PTR Hostname: static.71.4.105.178.clients.your-server.de
- Forward Resolution: Confirmed
- SPF/DMARC: Present on associated domain
- DNSSEC Valid: Yes
## Threat Assessment
Threat Indicators: None detected
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Abuse Confidence: Not applicable (low-risk classification)
Threat Persistence: No persistent malicious activity observed
## Observation History
The IP has generated 22 observation signals. Recent activity from June 2026 indicates:
- Provider classification: Hetzner cloud hosting
- Network classification: Cloud infrastructure
- No provider or organizational changes recorded
## Relationship Graph
The IP maintains 41 identified relationships:
- Primary DNS associations to hostnames under your-server.de
- Network associations within CLOUD-FSN1 subnet
- No organizational or certificate anomalies detected
## Neighborhood Analysis
Subnet: 178.105.4.0/24
- Abuse Density: 0.5 (50% of sibling IPs show activity)
- Classification: Mostly clean
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 1
Notable Neighbor: 178.105.4.138 (Risk Score: 25, Authority Score: 60)
## Security Recommendations
No immediate blocking or filtering actions recommended. The IP demonstrates characteristics consistent with legitimate cloud hosting infrastructure. Standard monitoring is sufficient.
Recommended Actions:
- Monitor for any changes in TLS certificate validity
- Continue routine traffic analysis
- No firewall rules required at this time
## Conclusion
IP 178.105.4.71 represents low-risk cloud infrastructure hosted on Hetzner's German network. The system shows no evidence of malicious activity, and its neighborhood analysis indicates a generally clean subnet. No immediate defensive action required; maintain standard monitoring protocols.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.71.4.105.178.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.71.4.105.178.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 25, 80, 3389, 8080 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | lab02.intalio.pl |
| Valid From | 2026-05-14T08:11:20+00:00 |
| Valid Until | 2031-05-13T08:11:20+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 1825 days |
| Serial Number | 1778746275 |
| Thumbprint | 0A80BD81EB92674830B0DB89DD0A9C540155B2D4 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-13 06:37:33 UTC |
| Last Seen | 2026-06-27 22:44:30 UTC |
| Profile Built | 2026-06-28 16:50:14 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.