IP Intelligence Briefing: 65.108.125.125
Date: 2026-06-15
---
**1. Core Profile**
- Risk Score: 20 (Low Risk)
- Provider: Hetzner Online GmbH (AS24940)
- Geolocation: Helsinki, Finland (FI)
- Network Role: Cloud compute infrastructure (Hetzner)
- Ownership: Hetzner Online GmbH (ARIN-regulated)
- Threat Indicators: No malicious activity detected (zero threat feeds, no spam, no known attackers).
---
**2. Observation History**
- First Seen: 2026-06-08
- Risk Trends: Stable low risk; no significant changes in threat signals.
- Geolocation Accuracy: Inferred with 750km radius (potential inaccuracies noted).
---
**3. Relationships**
- Network: Linked to Hetznerโs network (DE-HETZNER-20010209).
- DNS: Associated with `mail.documanager.es` (valid SPF/DMArc records).
- Subnet: Part of `65.108.125.0/24` (low abuse density, 1/2 sibling IPs flagged).
---
**4. Neighborhood Analysis**
- Subnet: `65.108.125.0/24` (abuse density: 0.5, classified as "mostly clean").
- Neighbors:
- `65.108.125.120` (risk score: 25, authority score: 60).
---
**5. Security Actions**
- Recommended Rules: None (low risk profile).
- Firewall: No action required; monitor for unexpected behavior.
---
**6. Summary**
The IP `65.108.125.125` is part of Hetznerโs cloud infrastructure in Finland, associated with a legitimate DNS hostname (`mail.documanager.es`). No threat indicators or malicious activity detected. While geolocation data is inferred, the subnet shows low abuse density. Monitor for anomalies, but no immediate action is required.
Next Steps: Verify DNS associations and ensure geolocation accuracy. Track subnet activity for potential lateral movement.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | 65.108.0.0/16 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | mail.documanager.es |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | mail.documanager.es |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 25, 3389, 8080 (4 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u3 |
๐ TLS Certificate
| SANs | documanager.es |
| Valid From | 2026-06-08T18:31:31+00:00 |
| Valid Until | 2026-09-06T18:31:30+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 05A1B7878DEA3AE526A1D5E8833BDCD964E4 |
| Thumbprint | 1B3E4E512086AD546369CA2D292C4FE8571DC386 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 24% | 3 | 4 |
| services | 35% | 2 | 3 |
| ownership | 24% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 29% | 13 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | High (85%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-17 03:09:25 UTC |
| Last Seen | 2026-06-28 04:43:02 UTC |
| Profile Built | 2026-06-28 22:47:04 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 32 |
Full dossier details are available via our API.