# IP Intelligence Briefing: 91.107.242.204
## Executive Summary
IP address 91.107.242.204 is classified as Low Risk with a risk score of 30. The IP operates within Hetzner Online GmbH's cloud infrastructure (AS24940) and presents no immediate threat indicators. The asset supports standard web services with one threat observation recorded in recent history.
---
## Network Profile
- Organization: Hetzner Online GmbH - Contact Role
- ASN: 24940 (CLOUD-NBG1)
- CIDR Block: 91.107.240.0/20
- Infrastructure Type: Cloud Compute / Hosting
- Reputation: Low Risk
---
## Geolocation Analysis
- Reported Location: Tehran, Iran (DE)
- Coordinates: 51.17°N, 10.45°E
- Accuracy Radius: 400 km
- Geolocation Consensus: True (1 source)
*Note: The Tehran geolocation appears inconsistent with Hetzner's primary data center locations in Germany. This may indicate a misconfigured server location declaration.*
---
## Technical Services
- Open Ports: 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH)
- SSH Banner: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
- TLS Certificate: Let's Encrypt (CN=prsim.me)
- DNS PTR: static.204.242.107.91.clients.your-server.de
- DNS Forward Resolution: Confirmed
- Email Auth: SPF enabled, DMARC not configured
---
## Threat Indicators
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- DNSBL Lists: 1 of 8 lists (dnsblListedCount)
---
## Neighborhood Assessment (91.107.242.204/24)
- Abuse Density: 1 (Low)
- Classification: mostly_clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
---
## Observation History
- Total Observations: 24
- Recent Activity: June 16, 2026
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
- Recent Signals:
- TLS/HTTP scanning activity
- Geolocation validation (RTT: 112-114ms)
- Operator score: 0.3478 (Basic classification)
- Subnet abuse density monitoring
---
## Relationship Graph
- Network Associations: Multiple links to CLOUD-NBG1 network
- DNS Associations: Primary hostname static.204.242.107.91.clients.your-server.de
- Control Plane: BGP prefix 91.107.128.0/17, Route stable: False
---
## Recommendations
- Monitoring Status: Continue standard observation
- Immediate Action: None required
- Firewall Rules: No blocking recommended based on current risk profile
- Investigation Priority: Low
---
## Conclusion
IP 91.107.242.204 operates as a legitimate cloud-hosted web server within Hetzner's infrastructure. The low risk score, absence of threat indicators, and clean neighborhood profile support continued monitoring without defensive intervention. The Tehran geolocation discrepancy warrants periodic verification but does not indicate malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | CLOUD-NBG1 |
| CIDR Block | 91.107.240.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.204.242.107.91.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.204.242.107.91.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | โ |
| Closed Ports | 25, 3389, 8443 (4 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 06:23:34 UTC |
| Last Seen | 2026-06-29 07:24:54 UTC |
| Profile Built | 2026-06-29 07:28:45 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.