IPDebrief

46.225.233.87

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 46.225.233.87/32

Classification: Moderate Risk (Score: 40)

Reporting Date: Current analysis based on available signal data

## 1. Ownership and Infrastructure

The IP address 46.225.233.87 is allocated to Hetzner Online GmbH (ASN 24940), a German cloud hosting provider. The address resides within the 46.224.0.0/15 BGP prefix, originating through AS6939 and AS24940. The network classification identifies this as a cloud compute infrastructure host with single-service purpose.

Geolocation Discrepancy: Primary geolocation data indicates Nuremberg, Bavaria, Germany. However, historical signal observations from 2026-06-15 recorded an alternative geolocation attribution to Iran (IR) via alienvault-otx with a reputation score of 0 and 13 associated threat pulses.

DNS Resolution: The IP resolves to `static.87.233.225.46.clients.your-server.de` under the domain `your-server.de`. Forward DNS resolution is confirmed.

## 2. Network Services

Active service enumeration reveals SSH on port 22/TCP with banner: `SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16`. No HTTP services or TLS certificates are currently observed. The infrastructure hosts single-service configurations typical of cloud compute environments.

## 3. Threat Indicators

## 4. Observation History

Signal observation history contains 24 recorded events. Notable temporal patterns include:

The IP is not flagged as persistently malicious. Threat observation count is 1 with 0 days of threat persistence.

## 5. Neighborhood Analysis

The /24 subnet (46.225.233.0/24) shows mixed neighborhood data:

## 6. Related Entities

Multiple relationship entities link to the following:

## 7. Recommended Security Actions

Based on risk assessment, the following firewall rules are recommended:

iptables:

```

iptables -A INPUT -s 46.225.233.87 -j DROP

```

nftables:

```

nft add rule inet filter input ip saddr 46.225.233.87 drop

```

Cloudflare WAF:

```json

{

"description": "Block 46.225.233.87 โ€” IPDebrief risk score 40",

"action": "block",

"filter": {

"expression": "ip.src eq 46.225.233.87"

}

}

```

AWS WAF:

```json

{

"Addresses": ["46.225.233.87/32"],

"Description": "IPDebrief risk 40"

}

```

## 8. Analyst Assessment

This IP address presents a moderate risk profile with conflicting geolocation signals. The primary Hetzner infrastructure attribution suggests legitimate cloud hosting, but historical IR geolocation signals and DNSBL listings indicate potential abuse or misconfiguration. The SSH service is standard for cloud infrastructure.

Key Indicators for Further Investigation:

1. Correlate the IR geolocation signal with actual traffic patterns

2. Review DNSBL listing reasons and associated reputation feeds

3. Monitor for connection attempts from this subnet to internal resources

4. Assess whether the single threat observation correlates with observed network activity

Risk Rating: MODERATE โ€” Block recommended pending correlation with internal threat intelligence.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionBavaria
CityNuremberg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationHetzner Online GmbH - Contact Role
ASNAS24940
Network Nameโ€”
CIDR Block46.224.0.0/15
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRstatic.87.233.225.46.clients.your-server.de
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesstatic.87.233.225.46.clients.your-server.de

๐Ÿ” DNS Hygiene

Hygiene Score100% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
27%
23
services
21%
22
ownership
27%
34
reputation
26%
13
geolocation
25%
22
Overall25%1218
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-19 15:39:12 UTC
Last Seen2026-06-28 09:22:01 UTC
Profile Built2026-06-29 03:27:32 UTC
Data FreshnessLive
Signal Types25
Total Observations29
๐Ÿ” 25 signal types ยท 29 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.