# IP Intelligence Briefing: 91.99.9.253
Classification: Moderate Risk (Score: 40)
Date: June 2026
Intel Source: IPDebrief Network Intelligence Platform
---
## Executive Summary
IP 91.99.9.253 is a single-service host within the Hetzner Online GmbH infrastructure in Falkenstein, Saxony, Germany. The IP demonstrates moderate risk characteristics with DNS blacklist presence but lacks definitive malicious indicators. Infrastructure is classified as hosting with active SSH service exposure.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 91.99.9.253/32 |
| **Risk Score** | 40 (Moderate Risk) |
| **ASN** | 24940 |
| **Organization** | Hetzner Online GmbH |
| **Location** | Falkenstein, Saxony, DE |
| **DNS Hostname** | static.253.9.99.91.clients.your-server.de |
| **Service Purpose** | Single-Service Host |
| **Infrastructure Type** | Cloud/Hosting |
---
## Network Infrastructure
- Provider: Hetzner Online GmbH (German hosting provider)
- Network Range: 91.99.0.0/16
- BGP Prefix: 91.99.0.0/16
- Route Stability: Unstable (route changes detected)
- Cloud Status: Hosted infrastructure identified
- ISP Classification: Hosting provider (not CDN, VPN, or proxy)
---
## Observed Services
Open Ports:
- TCP/22 (SSH): Open with banner "SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.2"
DNS Configuration:
- Forward resolution: Confirmed (1 hostname)
- PTR record: static.253.9.99.91.clients.your-server.de
- SPF Record: Present
- DMARC Record: Present
- Forward hostnames: 1 (your-server.de ecosystem)
---
## Threat Indicators
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Tor Exit Node | No |
| Known Spam Source | No |
| Active Campaigns | None detected |
| Blacklist Count | 2 of 8 total lists |
| DNSBL Listed | Yes (2 lists) |
---
## Neighborhood Analysis (91.99.9.0/24)
- Abuse Density: 1 (on scale 0-4)
- Subnet Classification: Mostly Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Inherited Risk Score: 2
- Risk Distribution: High (0), Medium (0), Low (0)
---
## Relationship Graph
- DNS Associations: static.253.9.99.91.clients.your-server.de (multiple entries)
- Network Associations: CLOUD-FSN1 (Hetzner cloud datacenter network)
- Total Relationships: 54 identified connections
- Primary Domain: your-server.de
---
## Observation History
Total Observations: 23 signals recorded
Recent Signals:
- June 28, 2026: Cloud infrastructure classification (confidence: 90%)
- June 20, 2026: Abuse density monitoring (confidence: 40%)
- June 20, 2026: Ownership stability signals (confidence: 85%)
- June 20, 2026: Threat list monitoring (confidence: 20%)
Temporal Indicators:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
- Threat Observation Count: 1
---
## Recommended Actions
Based on risk profile and observed signals, the following defensive measures are recommended:
Immediate Firewall Rules
iptables:
```
iptables -A INPUT -s 91.99.9.253 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 91.99.9.253 drop
```
nginx:
```
deny 91.99.9.253;
```
pfSense:
```
91.99.9.253/32
```
Cloudflare WAF:
```json
{
"description": "Block 91.99.9.253 โ IPDebrief risk score 40",
"action": "block",
"filter": {"expression": "ip.src eq 91.99.9.253"}
}
```
AWS WAF:
```json
{
"Addresses": ["91.99.9.253/32"],
"Description": "IPDebrief risk 40"
}
```
---
## Intelligence Assessment
IP 91.99.9.253 presents moderate risk due to DNS blacklist presence and routing instability within the Hetzner hosting infrastructure. While no active malicious campaigns or known attacker signatures have been identified, the IP's association with your-server.de and its position within the CLOUD-FSN1 datacenter network warrants continued monitoring.
The subnet-level analysis indicates one threat sibling within the /24, suggesting potential cluster-based activity. The SSH-only service configuration indicates this is a dedicated server host rather than a general-purpose endpoint.
Recommendation: Implement blocking measures per the firewall rules above, but consider the IP's hosting context and verify business justification before permanent takedown. Monitor for correlation with other your-server.de infrastructure IPs to determine if this represents isolated activity or coordinated behavior.
---
Generated by: IPDebrief Intelligence Platform
Classification: Defensive Security Intelligence
Authorization: SOC Analyst Review Required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.253.9.99.91.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.253.9.99.91.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.2 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 09:25:33 UTC |
| Last Seen | 2026-06-28 07:23:10 UTC |
| Profile Built | 2026-06-29 01:27:48 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.