# IP Intelligence Briefing: 5.9.98.210/32
## Executive Summary
IP 5.9.98.210 is a Hetzner cloud infrastructure address (AS24940) with a moderate risk score of 65/100. The IP is classified as clean subnet-level with no active threat indicators, though it appears on 3 of 8 DNSBL lists. Recommended action is monitoring with increased logging verbosity.
---
## Network Profile
| Attribute | Value |
|---|---|
| **IP Address** | 5.9.98.210/32 |
| **Risk Score** | 65/100 (Moderate Risk) |
| **Provider** | Hetzner Online GmbH (AS24940) |
| **Network** | HETZNER-fsn1-dc7 (5.9.98.192/27) |
| **Geolocation** | Berlin, Saxony, DE (Europe/Berlin) |
| **Infrastructure Type** | CloudCompute |
| **Ownership Stability** | Stable (0 ownership changes) |
| **Route Stability** | Unstable |
---
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 (major threat feeds)
- DNSBL Listed: 3/8 lists
- Campaign Correlation: No known campaigns
- Abuse Confidence Score: Not applicable
---
## DNS and Service Analysis
- PTR Hostname: static.210.98.9.5.clients.your-server.de
- Forward Resolution: Confirmed (1 hostname)
- Open Ports: None detected
- TLS Certificate: None
- HTTP Services: None
- Email Auth: SPF and DMARC configured for your-server.de
---
## Neighborhood Assessment
| Metric | Value |
|---|---|
| **Subnet** | 5.9.98.210/24 |
| **Abuse Density** | 0.0 (Clean) |
| **Threat Siblings** | 0 |
| **Active Siblings** | 0 |
| **Total Siblings** | 1 |
| **Classification** | Clean |
The /24 subnet shows no abuse activity, indicating this is an isolated moderate-risk endpoint rather than part of a larger attack infrastructure.
---
## Observation History
- Total Observations: 16
- Recent Activity: 2026-07-30 (last 48 hours)
- Threat Persistence Days: 0
- Persistently Malicious: No
- Ownership Changes: 0
Traceroute analysis confirms reachability with 12 hops. Recent signals show consistent geolocation and ownership data with no significant changes.
---
## Relationship Graph
6 relationships identified:
- DNS associations to static.210.98.9.5.clients.your-server.de
- Network associations to HETZNER-fsn1-dc7 subnet
No organization, certificate, or cross-network links detected.
---
## Recommended Actions
Priority: High (due to elevated risk score of 65)
Monitoring:
- Increase logging verbosity for traffic from this IP
- Review recent activity patterns
- Correlate with internal threat detection systems
Firewall Rules:
- iptables: `iptables -A INPUT -s 5.9.98.210 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 5.9.98.210 drop`
- nginx: `deny 5.9.98.210;`
- pfSense: `5.9.98.210/32`
- Cloudflare WAF: Block with expression `ip.src eq 5.9.98.210`
- AWS WAF: Address 5.9.98.210/32
---
## Analyst Notes
The elevated risk score (65) despite clean subnet classification and no active threat indicators suggests the risk may be derived from DNSBL listings (3/8) and route instability flags. The Hetzner cloud infrastructure designation indicates legitimate hosting services. Monitor for behavioral changes; implement recommended firewall rules if this IP appears in threat feeds or exhibits suspicious activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | HETZNER-fsn1-dc7 |
| CIDR Block | 5.9.98.192/27 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.210.98.9.5.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.210.98.9.5.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080 (3 open / 7 scanned) | ||
| Server | LiteSpeed |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | plesk.dnsbird.com |
| Valid From | 2026-07-29T01:49:34+00:00 |
| Valid Until | 2026-10-27T01:49:33+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 055CC830B5657A587496E58132FEA1A673CC |
| Thumbprint | 9F05504AC42B9117874305BD0F32B1B4700183C6 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims CH but primary geo says DE
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 02:42:07 UTC |
| Last Seen | 2026-08-12 19:19:40 UTC |
| Profile Built | 2026-08-12 19:27:35 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.