# IP Intelligence Briefing: 49.13.226.232
## Executive Summary
IP 49.13.226.232 is classified as Low Risk with an overall risk score of 25. The address is associated with Hetzner Online GmbH, a legitimate German cloud computing provider, operating within the Nuremberg data center region. No active threat campaigns or known malicious activity detected.
## Technical Profile
- IP Address: 49.13.226.232/32
- Risk Score: 25 (Low Risk)
- Provider: Hetzner Online GmbH (ASN 24940)
- Geolocation: Nuremberg, Bavaria, Germany (DE)
- Infrastructure Type: Cloud Compute / Hosting
- Network Block: 49.13.0.0/16
## Network Services
| Port | Protocol | Service | Status |
|---|---|---|---|
| 80 | TCP | HTTP | Open |
| 443 | TCP | HTTPS | Open |
| 22 | TCP | SSH | Open |
- Server Software: Caddy
- DNS Resolution: static.232.226.13.49.clients.your-server.de (your-server.de)
- Reverse DNS: Confirmed
- Certificate: None detected
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- DNSBL Listings: 1 of 8 total lists checked
- Campaign Likelihood: None
## Historical Analysis
Analysis of 22 signal observations indicates consistent operational patterns without malicious escalation. Recent activity (June 14, 2026) confirms:
- Stable provider attribution (Hetzner)
- Consistent Germany geolocation
- No persistent malicious behavior observed
- Connection failures noted on one observation
## Relationship Graph
43 relationships identified including:
- Network Associations: CLOUD-NBG1 (Hetzner Nuremberg cloud)
- DNS Associations: static.232.226.13.49.clients.your-server.de (multiple records)
## Neighborhood Assessment
- Subnet: 49.13.226.232/24
- Abuse Density: 1 (Low)
- Classification: Mostly Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
## Risk Distribution in Subnet
| Risk Level | Count |
|---|---|
| High | 0 |
| Medium | 0 |
| Low | 0 |
## Security Recommendations
1. SSH Monitoring: Port 22 is open. Implement SSH hardening if this IP is not expected to initiate connections.
2. DNSBL Verification: One DNSBL listing detected. Investigate specific list and assess impact.
3. Geolocation Validation: GeoPlausible flag not set. Consider additional validation if precise location is required.
4. Traffic Monitoring: Standard web traffic monitoring recommended for HTTP/HTTPS services.
5. No Immediate Action Required: Low-risk profile with no active threat indicators.
## Conclusion
IP 49.13.226.232 presents a low-risk operational profile consistent with legitimate cloud hosting infrastructure. No evidence of malicious activity, spam distribution, or attack participation. Standard security monitoring practices recommended. No immediate blocking or mitigation actions indicated.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.232.226.13.49.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.232.226.13.49.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Caddy |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-13 06:38:36 UTC |
| Last Seen | 2026-06-27 22:54:23 UTC |
| Profile Built | 2026-06-28 17:00:30 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.