IP Intelligence Briefing: 37.27.196.159
Date: 2026-06-13
---
**1. IP Profile**
- Risk Score: Moderate (40/100)
- Ownership: Hetzner Online GmbH (AS24940)
- Geolocation: Helsinki, Finland (FI)
- Network Role: CloudCompute (hosted by Hetzner)
- Threat Indicators: No active malicious signals (no malware, C2, or exploit indicators).
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- DNSBL listings (2/8 total) detected in DNS records.
- Consistent DNS resolution for `static.159.196.27.37.clients.your-server.de`.
- No spikes in threat signals or network anomalies.
- Stability: Stable network configuration; no recent ownership changes.
---
**3. Relationships**
- Network Associations:
- Linked to Hetzner's network (`DE-HETZNER-20111228`).
- DNS association with `your-server.de` (SPF/DMARC configured).
- No Direct Connections: No ties to known malicious entities, C2 servers, or botnets.
---
**4. Neighborhood Analysis**
- Subnet: `37.27.196.159/24`
- Neighbor Count: 0 (no active IPs in subnet).
- Abuse Density: 0% (no malicious activity in subnet).
---
**5. Recommendations**
- Monitor DNSBL Listings: Investigate why this IP is listed in 2 DNSBLs (e.g., spam or abuse history).
- Verify Domain Security: Ensure `your-server.de` adheres to SPF/DKIM/DMArc standards.
- Network Isolation: Given the isolated subnet and no active neighbors, consider enhanced monitoring for unexpected network changes.
Conclusion: This IP appears to be a legitimate Hetzner-hosted server with no active threats. However, the DNSBL listings warrant further investigation to rule out historical abuse or misconfigurations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | DE-HETZNER-20111228 |
| CIDR Block | 37.27.0.0/16 |
| RIR | RIPE |
| Country | FI |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.159.196.27.37.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.159.196.27.37.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.30.2 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2025-11-12T05:49:18+00:00 |
| Valid Until | 2026-11-12T05:49:18+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 01 |
| Thumbprint | B5FDA3D18EBC4EA3AF1E9FEAFFEBDA250548E07A |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 30% | 2 | 3 |
| ownership | 32% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 27% | 11 | 18 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims "" but primary geo says FI
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-07 07:50:21 UTC |
| Last Seen | 2026-06-21 13:45:36 UTC |
| Profile Built | 2026-06-21 13:50:20 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 29 |
Full dossier details are available via our API.