IP Intelligence Briefing: 188.40.199.50
Date: 2026-06-11
---
**1. Risk Profile**
- Risk Score: 50 (Moderate Risk)
- Provider: Hetzner Online GmbH (German cloud hosting provider)
- Geolocation: Falkenstein, Saxony, Germany (51.17°N, 10.45°E)
- Network Role: CloudCompute (firewalled, no services exposed)
- Threat Indicators: No active malicious activity detected.
---
**2. Observation History (Last 30 Days)**
- Threat Listings:
- Listed in 8 threat feeds (confidence: 85%), but no specific malicious campaigns or malware families linked.
- No DNS-based attacks or scanning observed.
- Network Stability:
- BGP route stability: Unstable (route changes detected).
- DNSSEC and CAA records validated, but operator score is low (0.3478).
---
**3. Relationships & Network Context**
- DNS Associations:
- Resolves to `static.50.199.40.188.clients.your-server.de` (owned by "your-server.de").
- SPF and DMARC records present but unverified.
- Network Subnet:
- Subnet: `188.40.199.50/24` (no active neighbors detected).
- Subnet abuse density: 0% (clean).
---
**4. Actionable Insights**
- Monitor:
- Track the IP for new threat listings or DNS changes, as it has a history of being flagged (even if confidence is low).
- Verify the ownership of `your-server.de` for potential phishing or spoofing risks.
- Mitigate:
- Ensure cloud server security configurations are up to date, given the moderate risk score.
- Consider blocking the IP in WAFs or firewalls if itβs part of a larger network with higher risk.
---
Conclusion:
188.40.199.50 is a cloud-hosted server with no current malicious activity detected. While it has a moderate risk score, the lack of active threats and clean subnet suggest it is likely a legitimate host. SOC teams should monitor for changes in threat listings or DNS behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | ALI-ESMAEILNEJAD |
| CIDR Block | 188.40.199.32/27 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | static.50.199.40.188.clients.your-server.de |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | static.50.199.40.188.clients.your-server.de |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | β |
π TLS Certificate
| SANs | amlakbeheshti.comwww.amlakbeheshti.commail.amlakbeheshti.comcpanel.amlakbeheshti.comwebmail.amlakbeheshti.comwebdisk.amlakbeheshti.comcpcontacts.amlakbeheshti.comcpcalendars.amlakbeheshti.comautodiscover.amlakbeheshti.com |
| Valid From | 2025-12-05T09:58:47+00:00 |
| Valid Until | 2026-12-05T09:58:47+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 011C43EE3A |
| Thumbprint | 6179F1CE2F57812D5A9D9B9BBB6DC1B5B06CCEE7 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-28 12:25:13 UTC |
| Last Seen | 2026-06-29 05:23:56 UTC |
| Profile Built | 2026-06-29 05:31:22 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.