## IP INTELLIGENCE BRIEFING: 204.168.170.128/32
Classification: Low Risk | Risk Score: 25/100 | Last Updated: 2026-06-29
OWNERSHIP & NETWORK ATTRIBUTES
The IP address 204.168.170.128 is hosted within the Hetzner Online GmbH infrastructure under AS24940 (CLOUD-HEL1 network). The CIDR block 204.168.160.0/20 was registered to Hetzner and operates as a cloud compute provider. Geolocation data places the infrastructure in Gunzenhausen, Germany (latitude/longitude unavailable), with DNS resolution pointing to the your-server.de domain.
INFRASTRUCTURE CLASSIFICATION
The endpoint operates as a cloud-hosted infrastructure with no open ports detected during scanning. Network classification indicates:
- Infrastructure Type: CloudCompute
- Hosting: Yes (isHosting flag set)
- Services: None exposed (no open ports, no TLS certificates, no HTTP banner)
- Connection Type: Firewalled/No services
The reverse DNS PTR record resolves to static.128.170.168.204.clients.your-server.de, and forward resolution is confirmed.
THREAT INDICATORS & BLACKLIST STATUS
No active threat indicators were identified:
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None
- Threat Persistence Days: 0 (not persistently malicious)
One DNSBL listing was detected (of 8 total lists checked), but the overall blacklist count remains zero. The control plane indicates route instability (isRouteStable: false) with no route changes in the last 30 days.
OBSERVATION HISTORY (23 TOTAL OBSERVATIONS)
Historical data spanning multiple observation periods shows:
- Subnet classification consistently rated as "mostly_clean" with abuse density of 1
- No ownership changes detected (0 changes)
- Threat observation count: 1
- No persistent malicious activity detected
- Recent signals (June 2026) maintain low-risk profiles with confidence scores ranging from 0.20 to 0.85
NEIGHBORHOOD ANALYSIS
The /24 subnet (204.168.170.128/24) shows:
- Abuse Density: 0 (low)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Classification: Mostly clean
- Inherited Risk: 2
No neighboring IPs were detected within the immediate subnet boundary.
RELATIONSHIP GRAPH (27 TOTAL LINKS)
Relationship analysis reveals:
- Multiple "Same Network" associations to CLOUD-HEL1 network entities
- DNS associations to static.128.170.168.204.clients.your-server.de
- No external organizational or certificate entity links beyond the network and DNS namespace
RECOMMENDED ACTIONS
Based on the risk profile, no specific security actions or firewall rules are recommended. The IP maintains a low-risk posture (25/100) with no actionable threat indicators. Standard monitoring is appropriate.
---
BRIEFING SUMMARY: IP 204.168.170.128 is a low-risk Hetzner cloud-hosted endpoint with no active threat indicators. The subnet demonstrates minimal abuse density, and historical observations confirm stable ownership with no persistent malicious activity. No immediate defensive actions required; continue standard monitoring.
THREAT LEVEL: LOW | SOC RECOMMENDATION: Monitor | BLOCK NEEDED: No
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | CLOUD-HEL1 |
| CIDR Block | 204.168.160.0/20 |
| RIR | ARIN |
| Country | FI |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.128.170.168.204.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.128.170.168.204.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-28 06:16:18 UTC |
| Last Seen | 2026-06-29 05:10:09 UTC |
| Profile Built | 2026-06-29 05:15:30 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.