# IP INTELLIGENCE BRIEFING: 91.98.112.31
Classification: Moderate Risk (Score: 55/100)
Date: 2026-06-21
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 91.98.112.31 is a cloud-hosted address operated by Hetzner Online GmbH (ASN 24940) in Nuremberg, Germany. The address maintains a moderate risk profile with 3 DNSBL listings across 8 threat intelligence feeds. While classified as "mostly_clean" within its /24 subnet, the IP exhibits hosting infrastructure characteristics and has triggered 1 threat observation.
---
## Ownership & Infrastructure
- Organization: Hetzner Online GmbH - Contact Role
- Netname: CLOUD-NBG1
- CIDR Block: 91.98.112.0/20
- Infrastructure Type: Cloud Compute / Hosting
- Service Purpose: Single-Service Host
- Control Plane: BGP prefix 91.98.0.0/16, Route stable: FALSE
---
## Geolocation
- Country: Germany (DE)
- Region: Bavaria
- City: Nuremberg
- Coordinates: 51.17°N, 10.45°E
- Timezone: Europe/Berlin
---
## Network Services & DNS
- Open Ports: TCP/80 (HTTP)
- Server Banner: Apache/2.4.58 (Ubuntu)
- HTTP Version: 1.1
- PTR Record: static.31.112.98.91.clients.your-server.de
- DNS Forward Confirmation: Yes
- Email Authentication: SPF: YES, DMARC: YES
- TLS Certificate: None detected
---
## Threat Indicators
- Reputation Sources: 0
- Blacklist Count: 0 (direct)
- DNSBL Lists: 3/8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaigns: None
- Threat Feeds: Empty
---
## Relationship Graph Analysis
The IP maintains 17 recorded relationships, primarily:
- DNS Associations: Multiple entries linking to hostname static.31.112.98.91.clients.your-server.de
- Network Relationships: Multiple CLOUD-NBG1 subnet associations
- Same Network: Consistent network-level groupings
---
## Subnet Neighborhood (91.98.112.0/24)
- Abuse Density: 1
- Classification: Mostly Clean
- Inherited Risk: 2
- Active Siblings: 1
- Threat Siblings: 1
- Total Siblings: 1
- Risk Distribution: High: 0, Medium: 0, Low: 0
---
## Historical Observations (24 Total)
Recent Activity:
- 2026-06-21: Routing and service signals observed (confidence: 60%)
- 2026-06-16: Subnet abuse density assessment completed
- Ownership Changes: 0
- Threat Persistence: 0 days
- Persistently Malicious: No
Temporal Analysis: The IP shows minimal ownership changes and no persistent malicious activity detected. Threat observation count remains at 1.
---
## Recommended Actions
- Current Status: Monitor (Moderate Risk)
- Firewall Rules: No specific rules recommended (empty action set)
- Block Decision: Consider selective blocking based on threat context
- Investigation Priority: Medium
---
Conclusion: IP 91.98.112.31 presents a moderate risk profile consistent with cloud hosting infrastructure. The single threat observation and 3 DNSBL listings warrant monitoring but do not indicate active malicious activity. The subnet shows low abuse density with minimal threat sibling presence. Recommend continued observation with standard logging policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | CLOUD-NBG1 |
| CIDR Block | 91.98.112.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.31.112.98.91.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.31.112.98.91.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Apache/2.4.58 (Ubuntu) |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-02 12:04:43 UTC |
| Last Seen | 2026-06-21 08:55:13 UTC |
| Profile Built | 2026-06-21 09:02:29 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 30 |
Full dossier details are available via our API.