IPDebrief

195.201.22.39

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP INTELLIGENCE BRIEFING: 195.201.22.39

Classification: LOW RISK INFRASTRUCTURE ASSET

Date: 2026-06-15

---

EXECUTIVE SUMMARY

IP address 195.201.22.39 is a low-risk infrastructure resource operated by Hetzner Online GmbH, associated with their Nuremberg (DE) cloud infrastructure (CLOUD-NBG1). The IP demonstrates stable routing patterns, no malicious threat indicators, and belongs to a clean neighborhood subnet. No immediate defensive action required.

---

OWNERSHIP & GEOSOCIAL DATA

---

RISK ASSESSMENT

MetricValueAssessment
**Overall Risk Score**25Low Risk
**Abuse Confidence Score**Not FlaggedNo Threat
**Blacklist Count**0Clean
**Known Attacker**FalseNot Malicious
**Spam Source**FalseNot Abusive
**Tor Exit Node**FalseNot Anonymizer
**Risk Breakdown**Provider: 0, Authority: 0Legitimate Provider

Control Plane Indicators:

---

NETWORK & SERVICE PROFILE

---

THREAT INTELLIGENCE

Current Threat Indicators: None

DNSBL Status: Listed on 1 of 8 DNSBL lists (minor listing, requires context)

---

OBSERVATION HISTORY

Total Signals Observed: 21

Temporal Analysis:

---

RELATIONSHIP GRAPH

DNS Associations:

Network Relationships:

---

NEIGHBORHOOD ANALYSIS (195.201.22.0/24)

---

RECOMMENDATIONS

SOC Analyst Action: Monitor only; no blocking recommended.

This IP represents legitimate cloud infrastructure from Hetzner's Nuremberg data center. The absence of open ports and services, combined with stable routing and clean threat indicators, indicates this is a standard infrastructure endpoint rather than an active threat actor. The single DNSBL listing is likely a minor false positive or non-critical listing that does not warrant blocking.

Firewall Rule Recommendation: Allow (no action needed)

Alerting Threshold: Monitor for any new threat indicators or behavioral changes

---

Data Source: IPDebrief Intelligence Platform

Confidence Level: High

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionBavaria
CityNuremberg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationHetzner Online GmbH - Contact Role
ASNAS24940
Network NameCLOUD-NBG1
CIDR Block195.201.16.0/21
RIRRIPE
CountryDE
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRstatic.39.22.201.195.clients.your-server.de
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesmail.skeith.net

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=mail.skeith.net
Issued by CN=R13, O=Let's Encrypt, C=US
Self-signed: No
SANsautoconfig.skeith.netautodiscover.skeith.netmail.skeith.net
Valid From2026-05-24T15:59:38+00:00
Valid Until2026-08-22T15:59:37+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number05258E7B786C3F003525D057B892847111F6
Thumbprint51A199E93D53A031B35D745D06B05F720EED5F12

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
23
routing
33%
23
services
29%
24
ownership
35%
36
reputation
31%
13
geolocation
39%
23
Overall33%1222
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-17 03:08:13 UTC
Last Seen2026-06-28 04:22:39 UTC
Profile Built2026-06-28 22:27:10 UTC
Data FreshnessLive
Signal Types25
Total Observations31
๐Ÿ” 25 signal types ยท 31 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.