IPDebrief

46.224.175.215

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 46.224.175.215/32

## Executive Summary

IP address 46.224.175.215 was identified as a moderate-risk (score: 40) cloud computing endpoint operated by Hetzner Online GmbH in Falkenstein, Germany. The IP resolves to your-server.de and hosts web services on ports 80/443 with SSH access on port 22. Network analysis indicates a low-abuse-density subnet (46.224.175.0/24) with minimal correlated threat activity.

## Technical Profile

AttributeValue
**ASN**24940 (Hetzner Online GmbH)
**Location**Falkenstein, Saxony, Germany (51.17°N, 10.45°E)
**Infrastructure Type**CloudCompute/Hosting
**Network Classification**Cloud hosting environment
**DNS Resolution**static.215.175.224.46.clients.your-server.de
**SSL Certificate**TRAEFIIK DEFAULT CERT (self-signed)
**Open Ports**22/SSH, 80/HTTP, 443/HTTPS
**HTTP Status**404 (Not Found)

## Threat Indicators

The IP does not match any known attack campaigns or threat feeds. However, the moderate risk score warrants monitoring due to the hosting infrastructure classification.

## Neighborhood Analysis

Subnet 46.224.175.0/24 exhibits low abuse density (score: 0) with classification "mostly_clean." One neighbor IP (46.224.175.79) showed moderate risk (score: 25). The subnet inherited risk score of 5, indicating limited correlation with known malicious activity at the network level.

## Historical Observations

25 observations captured over the analysis period. Recent signals confirm consistent cloud infrastructure classification with Hetzner provider attribution. HTTP fingerprinting revealed HTTP/2.0 support with 358ms TTFT and missing security headers (CSP, HSTS, X-Frame-Options). Email authentication (SPF/DMARC) status was not validated for the associated domain.

## Recommended Security Actions

Based on the risk profile, the following defensive measures are recommended:

Immediate Blocking Rules:

```bash

# iptables

iptables -A INPUT -s 46.224.175.215 -j DROP

# nftables

nft add rule inet filter input ip saddr 46.224.175.215 drop

# nginx

deny 46.224.175.215;

# pfSense

46.224.175.215/32

# Cloudflare WAF

Block 46.224.175.215 โ€” IPDebrief risk score 40

# AWS WAF

Addresses: 46.224.175.215/32

```

Analysis Notes:

## Conclusion

The IP represents a moderate-risk cloud endpoint with no definitive malicious indicators. Blocking is recommended as a precautionary measure consistent with Hetzner's hosting infrastructure profile. Continued monitoring advised to track any changes in reputation or threat indicators.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionSaxony
CityFalkenstein
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationHetzner Online GmbH - Contact Role
ASNAS24940
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRstatic.215.175.224.46.clients.your-server.de
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesstatic.215.175.224.46.clients.your-server.de

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.2

๐Ÿ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
โš ๏ธ
CN=TRAEFIK DEFAULT CERT
Issued by CN=TRAEFIK DEFAULT CERT
Self-signed: Yes
SANs4723ef24767d6bc50568372d48b5fd9d.b2352daba7554d5cf43af62b0df2ab58.traefik.default
Valid From2026-06-06T07:47:20+00:00
Valid Until2027-06-06T07:47:20+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_128_GCM_SHA256
Signature Algorithmsha256RSA
Validity Period365 days
Serial Number6CA0898507D12E48D21D5E5C573532E2
ThumbprintE17368655755A85A774416239964E1E035222080

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
24
routing
13%
11
services
28%
23
ownership
24%
23
reputation
30%
13
geolocation
35%
23
Overall26%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: IR, DE

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-18 15:27:01 UTC
Last Seen2026-06-28 07:39:16 UTC
Profile Built2026-06-29 07:47:25 UTC
Data FreshnessLive
Signal Types24
Total Observations28
๐Ÿ” 24 signal types ยท 28 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.