# INTELLIGENCE BRIEFING: 46.224.75.227/32
## Executive Summary
IP 46.224.75.227 presents a moderate risk profile (risk score: 40) with evidence of conflicting geolocation data. While the IP resolves to Hetzner hosting infrastructure in Falkenstein, Germany, historical observations include Iranian location attribution with threat indicators. The address is classified as a single-service host with SSH access and is listed on 2 of 8 DNSBLs.
## Technical Profile
- IP Address: 46.224.75.227/32
- Risk Score: 40/100 (Moderate Risk)
- Provider: Hetzner Online GmbH (AS24940)
- Geolocation: Falkenstein, Saxony, Germany (51.17°N, 10.45°E)
- DNS: static.227.75.224.46.clients.your-server.de (your-server.de)
- Classification: Hosting infrastructure, Single-Service Host
- Open Ports: TCP/22 (SSH - OpenSSH_10.0p2 Debian)
- Control Plane: BGP prefix 46.224.0.0/15, route changes observed in last 30 days
- DNSBL Status: Listed on 2 of 8 blacklists
## Key Indicators
- DNSBL Listings: 2 confirmed listings across 8 total DNSBLs
- Geolocation Discrepancy: Primary profile shows German location, but one historical observation (2026-06-28) attributed the IP to Iran (AS56402) with active threat indicators
- Historical Observations: 22 total signals recorded, including infrastructure classification and your-server.de domain associations
- Subnet Analysis: /24 neighborhood (46.224.75.0/24) shows zero abuse density with no neighboring risk signals
- Persistence: Not classified as persistently malicious; ownership has remained stable
## Threat Context
The geolocation discrepancy between the Hetzner/German primary profile and Iranian attribution with threat signals warrants investigation. This could indicate:
- IP reuse or hijacking
- Routing anomalies
- False attribution by threat feeds
- Legitimate multi-tenant hosting with legitimate traffic
## Recommended Actions
Based on the moderate risk profile and DNSBL listings, consider the following:
- Block at perimeter firewall (iptables/nftables)
- Add to WAF rulesets (Cloudflare/AWS)
- Monitor for continued activity rather than immediate block if business needs exist
Firewall rules provided by IPDebrief:
- iptables: `iptables -A INPUT -s 46.224.75.227 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 46.224.75.227 drop`
- nginx: `deny 46.224.75.227;`
## SOC Analyst Notes
- Verify traffic patterns before implementing block rules
- The IP has legitimate hosting infrastructure characteristics (your-server.de, Hetzner ASN)
- Investigate the Iranian attribution if the IP is generating suspicious traffic
- No direct evidence of active malicious activity despite DNSBL listings and conflicting geolocation data
- Consider whitelist if this is a known legitimate service requiring this IP range
---
*Generated: 2026-06-28*
*Data Sources: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.227.75.224.46.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.227.75.224.46.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 23:40:12 UTC |
| Last Seen | 2026-06-28 12:55:11 UTC |
| Profile Built | 2026-06-29 07:01:00 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.