# THREAT INTELLIGENCE BRIEFING
Target: 91.98.170.2/32
Classification: Moderate Risk
Generated: 2026-08-13
Analyst: IPDebrief Intelligence Platform
---
## EXECUTIVE SUMMARY
IP 91.98.170.2 is a cloud infrastructure address hosted by Hetzner Online GmbH (ASN 24940) in Nuremberg, Germany. The IP registers a moderate risk score of 55/100 with elevated monitoring recommendations. The address is classified as cloud compute infrastructure with no currently detected malicious indicators.
---
## OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| **Organization** | Hetzner Online GmbH - Contact Role |
| **ASN** | 24940 |
| **Network Block** | 91.98.160.0/20 (CLOUD-NBG1) |
| **Country** | Germany (DE) |
| **Region** | Bavaria |
| **City** | Nuremberg |
| **Infrastructure Type** | CloudCompute |
| **Hosting Provider** | Yes |
The IP resolves to the hostname `static.2.170.98.91.clients.your-server.de` via forward DNS, with SPF and DMARC authentication records present on the owning domain.
---
## THREAT PROFILE
Risk Score: 55/100 (Moderate)
Threat Indicators:
- No known attacker reputation
- Not a Tor exit node
- Not identified as spam source
- Blacklist count: 0
- DNSBL listings: 3/8 total lists
Network Classification:
- Cloud infrastructure with firewalled/no services detected
- No open ports observed
- No TLS certificate or HTTP banner detected
- BGP prefix stable: 91.98.0.0/16 (Hetzner)
---
## OBSERVATION HISTORY
Total Signals: 14 observations
Recent signal activity (2026-08-13) confirms:
- Consistent geolocation to Germany (DE) with 0.70 confidence
- Multiple provider verification signals confirming Hetzner ownership (0.90-0.95 confidence)
- Cloud infrastructure classification verified (0.90 confidence)
- No observed behavioral changes over the monitoring period
---
## NEIGHBORHOOD ANALYSIS
Subnet: 91.98.170.0/24
- Active neighbors: 0
- Abuse density: 0%
- High-risk siblings: 0
- Medium-risk siblings: 0
- Low-risk siblings: 0
The immediate /24 subnet shows no adjacent threat activity.
---
## RECOMMENDED ACTIONS
Risk Level: High (based on elevated risk score)
Firewall Actions:
- `iptables -A INPUT -s 91.98.170.2 -j DROP`
- `nft add rule inet filter input ip saddr 91.98.170.2 drop`
- `nginx deny 91.98.170.2;`
Monitoring Recommendations:
- Increase logging verbosity for traffic from this IP
- Review recent connection activity and payload patterns
- Evaluate DNS query logs for anomalous behavior
WAF Integration:
- Cloudflare: Block IP 91.98.170.2 (Expression: `ip.src eq 91.98.170.2`)
- AWS WAF: Create rule for 91.98.170.2/32 with description "IPDebrief risk 55"
---
## CONCLUSION
IP 91.98.170.2 presents a moderate risk profile attributable to its classification as cloud hosting infrastructure. While no active threat indicators were detected, the elevated risk score warrants enhanced monitoring. Recommended actions include increased logging and consideration of blocking in perimeter defenses pending further context. The IP is associated with a stable Hetzner network block with no adjacent threat activity in the immediate neighborhood.
Status: Monitor / Evaluate for Block
Priority: Medium-High
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | CLOUD-NBG1 |
| CIDR Block | 91.98.160.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.2.170.98.91.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.2.170.98.91.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | openresty |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-07 07:33:54 UTC |
| Last Seen | 2026-08-30 16:22:59 UTC |
| Profile Built | 2026-09-03 17:56:37 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 30 |
Full dossier details are available via our API.