IP INTELLIGENCE BRIEFING: 46.62.239.90/32
EXECUTIVE SUMMARY
The IP address 46.62.239.90 is a cloud-hosted infrastructure endpoint operating under Hetzner Online GmbH (AS24940) with a moderate risk profile (65/100). The IP resolves to Helsinki, Finland and is configured as a multi-service cloud host. While not explicitly flagged as a known attacker or spam source, the IP exhibits elevated risk indicators including DNS blacklist listings (3/8 total lists) and historical geolocation discrepancies.
OWNERSHIP & GEOLOCATION
- ISP/Provider: Hetzner Online GmbH (AS24940)
- Location: Helsinki, Uusimaa, Finland (FI)
- Infrastructure Type: Cloud Compute / Multi-Service Host
- Network Classification: Cloud hosting environment (CLOUD-HEL1)
- DNS Resolution: static.90.239.62.46.clients.your-server.de (your-server.de domain)
THREAT INDICATORS
- Risk Score: 65 (Moderate Risk)
- DNSBL Listings: 3 of 8 total blacklists
- Operator Score: 0.3478 (Basic classification)
- Known Campaigns: None identified
- Tor/VPN/Proxy: Not detected
- HTTP Status: 403 Forbidden
NETWORK SERVICES
- Port 80 (HTTP): Apache/2.4.62 (AlmaLinux)
- Port 22 (SSH): OpenSSH_8.7
- Security Headers: HSTS, CSP, and referrer policy not implemented
TEMPORAL ANALYSIS
The IP has been observed 25 times across multiple signal types. Historical data indicates geolocation inconsistenciesโmost recent observations (2026-06-19) show conflicting location data with Iranian coordinates (IR) from AlienVault OTX feeds, despite the primary geolocation database reporting Helsinki. This discrepancy warrants attention for potential spoofing or compromised routing.
NEIGHBORHOOD CONTEXT
The /24 subnet (46.62.239.0/24) shows:
- Abuse Density: 1 (Low to Moderate)
- Total Siblings: 2 active IPs
- Threat Siblings: 2 flagged
- Neighbor Analysis: One neighbor (46.62.239.178) shows risk score 15 with authority score 60
RELATIONSHIP GRAPH
113 relationships identified, primarily network-level associations to Hetzner CLOUD-HEL1 infrastructure, indicating this is part of a broader cloud hosting cluster rather than a standalone endpoint.
RECOMMENDED ACTIONS
Immediate:
- Implement blocking or rate-limiting for 46.62.239.90/32 at perimeter firewalls
- Increase logging verbosity for all traffic from this IP
- Review recent activity for potential abuse patterns
Firewall Rules:
- iptables: `iptables -A INPUT -s 46.62.239.90 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 46.62.239.90 drop`
- nginx: `deny 46.62.239.90;`
- AWS WAF: `Addresses: ["46.62.239.90/32"]`
MONITORING:
- Track geolocation consistency over time (IR vs FI discrepancy)
- Monitor for changes in DNSBL listings
- Observe HTTP response patterns (current 403 status)
RISK ASSESSMENT: The IP represents moderate risk primarily due to cloud infrastructure hosting common for both legitimate and malicious purposes. The DNS blacklist presence and geolocation inconsistencies suggest potential abuse activity. Recommend defensive blocking combined with enhanced monitoring to validate actual threat activity before implementing permanent filtering policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.90.239.62.46.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.90.239.62.46.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | Apache/2.4.62 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 24% | 2 | 4 |
| ownership | 17% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 18 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 05:02:19 UTC |
| Last Seen | 2026-06-27 12:44:04 UTC |
| Profile Built | 2026-06-28 06:49:20 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 31 |
Full dossier details are available via our API.