IP Intelligence Briefing: 95.217.209.212
*Generated via IPDebrief tools*
---
1. Core Profile
- Risk Score: Moderate (50/100)
- Provider: Hetzner Online GmbH (ASN 24940)
- Geolocation: Registered to Finland (FI), but inferred location shows Germany (D-91710 Gunzenhausen) with 750km accuracy radius.
- Network Role: CloudCompute infrastructure (hosted, no residential/mobile traits).
- Threat Status: No malicious indicators, zero spam/ransom/campaign associations.
2. Observation History
- Recent Activity:
- Geolocation inferred via multi-signal analysis (confidence: 28%)
- DNS listings detected (8 total lists, 1 high-severity threat feed)
- Subnet abuse density remains 0% over 30 days
- Stability: No ownership changes or persistent malicious behavior.
3. Network Relationships
- Linked Entities:
- Same network: `CLOUD-HEL1` (Hetzner's subnet)
- DNS association: `net.thewebstage.com` (PTR confirmed)
- No BGP/AS Relationships: No peerings or route anomalies detected.
4. Subnet Analysis
- Subnet: `95.217.209.212/24`
- Neighbor Activity: Zero active IPs in subnet (abuse density: 0%).
- Isolation: No sibling IPs detected, suggesting isolated host.
5. Recommendations
- Monitoring: Track DNS (net.thewebstage.com) for domain changes.
- Threat Mitigation: No immediate action required; IP is clean with no active threats.
- Context: Hetzner's infrastructure is generally reputable, but verify geolocation discrepancies.
---
Conclusion: This IP is a low-risk cloud-hosted server with no malicious activity. Monitor for unexpected DNS changes or subnet activity, but no defensive action is warranted at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | CLOUD-HEL1 |
| CIDR Block | 95.217.208.0/20 |
| RIR | RIPE |
| Country | FI |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | net.thewebstage.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | net.thewebstage.com |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 8080 | http-alt | tcp | โ |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 22, 25, 3389 (4 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-04-06T07:01:18+00:00 |
| Valid Until | 2036-04-03T07:01:18+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
| Serial Number | 6CF199799FC38FCC3D57EB3F6AAF6D4EF56221C5 |
| Thumbprint | 881E12EF0791419B6B92CCE02964339DD6F93336 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 20% | 9 | 13 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims US but primary geo says FI
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-28 12:26:22 UTC |
| Last Seen | 2026-06-29 05:35:24 UTC |
| Profile Built | 2026-06-29 05:38:13 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 26 |
Full dossier details are available via our API.