IPDebrief

188.34.190.189

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 188.34.190.189/32

Date: June 2026

Classification: Moderate Risk

Analyst: IPDebrief Intelligence Platform

---

## Executive Summary

IP address 188.34.190.189 is a hosting infrastructure endpoint operated by Hetzner Online GmbH in Falkenstein, Saxony, Germany. The IP exhibits moderate-risk characteristics (risk score: 40) primarily due to DNSBL listings and operator classification. No direct threat indicators were observed, though the IP is associated with a known hosting environment (your-server.de) and should be monitored for potential abuse escalation.

---

## Technical Profile

Ownership & Network:

Geolocation:

Network Role:

---

## Services & DNS

Open Ports:

PortProtocolService
80TCPHTTP
443TCPHTTPS
22TCPSSH

DNS Resolution:

Email Authentication:

TLS Certificate:

Web Server:

---

## Threat Intelligence

Risk Indicators:

Control Plane:

---

## Observation History

Temporal Analysis:

Key Historical Signals:

Trend: IP profile has remained stable with no significant risk escalation detected over the observation period.

---

## Network Relationships

Relationship Count: 52 associations

Key Associations:

Campaign Correlation:

---

## Neighborhood Analysis

Subnet: 188.34.190.189/24

Metrics:

Risk Distribution: High: 0, Medium: 0, Low: 0

---

## Recommended Actions

Security Recommendations:

No specific security recommendations generated due to moderate risk profile and lack of direct threat indicators. However, the following firewall rules are available for consideration:

Firewall Rules:

iptables:

```

iptables -A INPUT -s 188.34.190.189 -j DROP

```

nftables:

```

nft add rule inet filter input ip saddr 188.34.190.189 drop

```

nginx:

```

deny 188.34.190.189;

```

pfSense:

```

188.34.190.189/32

```

Cloudflare WAF:

```json

{

"description": "Block 188.34.190.189 β€” IPDebrief risk score 40",

"action": "block",

"filter": {

"expression": "ip.src eq 188.34.190.189"

}

}

```

AWS WAF:

```json

{

"Addresses": ["188.34.190.189

AWS WAF:

```json

{

"Addresses": ["188.34.190.189/32"],

"Description": "IPDebrief risk 40"

}

```

---

## Threat Assessment

Current Risk Level: Moderate Risk (40/100)

Key Risk Factors:

Mitigating Factors:

---

## Intelligence Conclusions

IP address 188.34.190.189 presents a moderate-risk profile consistent with standard hosting infrastructure. The IP is owned by Hetzner Online GmbH, a legitimate cloud hosting provider, and operates legitimate services (web, SSH, HTTPS). While the IP shows some DNSBL listings and moderate operator classification, no active malicious behavior has been observed in the historical record.

Recommended SOC Actions:

1. Monitor for increased abuse activity or escalation in threat signals

2. Review any security alerts generated from this IP range

3. Consider adding to watchlist for intelligence correlation

4. Evaluate against existing threat intelligence feeds for context

Priority: Low-Medium

Action Required: Monitor and Correlate

---

*Report generated by IPDebrief Intelligence Platform. Data sourced from network probes, DNS lookups, and threat intelligence feeds as of June 2026.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡©πŸ‡ͺ Germany
RegionSaxony
CityFalkenstein
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

🏒 Ownership & Registration

OrganizationHetzner Online GmbH - Contact Role
ASNAS24940
Network Nameβ€”
CIDR Block188.34.128.0/17
RIRRIPE
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRstatic.189.190.34.188.clients.your-server.de
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesmail.flotiva.app

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 2 β€” Moderate operator sophistication with routing hygiene
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.2

πŸ” TLS Certificate

πŸ”’
CN=mail.flotiva.app
Issued by CN=YR1, O=Let's Encrypt, C=US
Self-signed: No
SANsmail.flotiva.app
Valid From2026-06-03T19:34:54+00:00
Valid Until2026-09-01T19:34:53+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number06F46AC049CF8D77CB4F9C755C11D24D9480
Thumbprint061D5251F290B330A6ABBA9377EE18F697417CA4

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
22%
24
routing
30%
34
services
29%
24
ownership
27%
34
reputation
26%
13
geolocation
33%
23
Overall28%1322
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionHigh (85%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-14 13:24:14 UTC
Last Seen2026-06-28 00:50:51 UTC
Profile Built2026-06-28 18:56:35 UTC
Data FreshnessLive
Signal Types29
Total Observations33
πŸ” 29 signal types Β· 33 observations collected
This report is generated from 29+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.