# IP Intelligence Briefing: 65.21.31.180/32
Classification: Low Risk Cloud Infrastructure
Date of Analysis: 2026-06-26
Risk Score: 25/100 (Low Risk)
---
## Executive Summary
IP 65.21.31.180 is a low-risk cloud computing host operated by Hetzner Online GmbH in Helsinki, Finland. The IP exhibits legitimate hosting characteristics with no persistent malicious activity. No immediate blocking recommendations are warranted, though standard monitoring is advised due to one DNSBL listing and one threat sibling in the local subnet.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **ASN** | 24940 (Hetzner Online GmbH) |
| **Organization** | Hetzner Online GmbH - Contact Role |
| **Country** | Finland (FI) |
| **City** | Helsinki, Uusimaa |
| **CIDR Block** | 65.21.0.0/16 |
| **Infrastructure Type** | Cloud Compute / Hosting |
| **DNS** | static.180.31.21.65.clients.your-server.de |
| **Hosted Domain** | your-server.de |
| **Open Ports** | TCP/22 (SSH) |
---
## Threat Assessment
Current Risk Indicators:
- Risk Score: 25 (Low)
- Abuse Confidence: Not flagged as known attacker
- Tor/Proxy: Not a Tor exit node or proxy
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Known Campaigns: None detected
- Spam Source: Not flagged
Network Role:
- Cloud-hosted infrastructure (Hetzner provider)
- Single-service host configuration
- DNS records verified (forward resolution confirmed)
- Email authentication: SPF and DMARC configured
---
## Historical Observations
Analysis of 21 observation signals reveals stable behavior with no escalating threat patterns:
- Ownership Stability: No changes detected
- Threat Persistence: 0 days
- Signal Types Observed: DNS, geolocation, network classification, routing
- Most Recent: 2026-06-26
The IP demonstrates consistent infrastructure classification and geographic attribution to Finland with moderate confidence (28-90% across signals).
---
## Relationship Graph
54 relationships identified:
- DNS Associations: your-server.de domain (verified)
- Network Links: Hetzner network infrastructure (DE-HETZNER-20010926)
- Classification: Standard cloud hosting with no anomalous associations
---
## Neighborhood Analysis
Subnet: 65.21.31.180/24
- Abuse Density: 1 (classified as "mostly_clean")
- Total Siblings: 1 active sibling IP
- Threat Siblings: 1 identified in neighborhood
This indicates minimal neighborhood-level abuse risk, though one related IP warrants monitoring.
---
## Recommended Actions
Firewall Rules: None recommended at this time.
Monitoring Level: Standard traffic monitoring advised.
Blocking Threshold: Not recommended given low risk score (25).
Rationale: The IP exhibits characteristics of legitimate cloud hosting infrastructure. The single DNSBL listing and one threat sibling in the subnet do not justify blocking. Standard logging and monitoring should continue.
---
Analyst Notes: This IP should be treated as legitimate cloud infrastructure. No immediate threat action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.180.31.21.65.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.180.31.21.65.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 22:17:57 UTC |
| Last Seen | 2026-06-27 18:42:26 UTC |
| Profile Built | 2026-06-28 12:49:39 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.