Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Hetzner Finland Oy

Hetzner Finland Oy Vendor Cyber Rating & Cyber Score

hetzner.com

The companies within the Hetzner Group provide private and business clients with high-performance hosting products as well as the necessary infrastructure for the efficient operation of websites. Hetzner Finland Oy was founded in 2015 as part of the Group, and it benefits from the expertise of Hetzner Online GmbH in Germany. The Hetzner Data Center Park Helsinki, with its state of the art data solutions, will serve Hetzner clients worldwide.


HFO A.I CyberSecurity Scoring

HFO
Company Information
Website:http://hetzner.com
Employees number:32
Number of followers:1,275
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:hetzner.com
HFO Risk Score (AI oriented)
Between 700 and 749
logo
HFOIT Services and IT Consulting
Updated:
19/03/2026
733/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
HFO Global Score (TPRM)
xxxx
logo
HFOIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

HFO
HFOModerate
Current Score
733Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
735Before Incident
JUNE 2026
735Before Incident
MAY 2026
734Before Incident
APRIL 2026
734Before Incident
MARCH 2026
733Before Incident
FEBRUARY 2026
750Before Incident
Cyber Attack
14 Feb 2026HFO
Hetzner and Dade Samane Fanava Company: Iran-Linked Botnet Exposed After Open Directory Leak Reveals 15-Node Relay Network

Iranian Server Misconfiguration Exposes Censorship-Bypass Relay and SSH Botnet Operation

732After Incident
LOW-18
HETFAN1773908769
Iranian Server Misconfiguration Exposes Censorship-Bypass Relay and SSH Botnet Operation Researchers at Hunt.io uncovered a misconfigured open directory on an Iranian server, revealing a live censorship-bypass relay and SSH-based botnet infrastructure operated by a single actor. The discovery highlights how low-sophistication threat actors can repurpose techniques associated with Iranian advanced persistent threat (APT) groups for financial or personal gain. The exposed server, hosted by Iranian ISP Dade Samane Fanava Company (PJS) at 185.221.239[.]162, contained 449 files across 59 subdirectories, including a .bash_history file, MHDDOS installer, C-based flood tools, and botnet components. A shared Let’s Encrypt TLS certificate for *.server21[.]org linked the server to 14 additional IPs, split between Hetzner (Finland) and Iranian ISPs, forming a purpose-built relay network. The operation combined censorship circumvention with DDoS capabilities. A config-client.yaml file revealed a KCP-based Paqet tunnel, commonly used in Persian-language communities to bypass Iranian filtering, forwarding traffic to a Hetzner node (65.109.187[.]102). While appearing as a VPN relay, the server also hosted MHDDOS and custom SYN/UDP flood tools, targeting a FiveM GTA server (5.42.223[.]60:30120) and a web host (194.147.222[.]151:80/443). The bash history allowed researchers to reconstruct the operation’s phases: - Initial deployment of Paqet, GRE forwarders, and 3x-ui for censorship bypass. - DDoS tooling, including compilation of syn.c and flood.c. - Botnet build-out, with scripts (ohhhh.py, yse.py) automating SSH-based infections. The ohhhh.py script opened 500 concurrent SSH sessions, uploaded and compiled cnc.c on victims, and launched it in detached screen sessions for persistence. The yse.py script acted as a kill switch, terminating processes across infected hosts. While the cnc.c source was not recovered, strings in the binary revealed a flood-focused botnet ("BOT CLIENT v1.0") with reconnection logic and attack commands. Attribution signals point to an Iran-based operator: - Hosting on Iranian ISPs and ArvanCloud DNS for server21[.]org. - Use of Paqet "kharej" configurations, tailored for Iranian censorship. - Farsi inline comments in scripts. However, the opportunistic targeting of a game server and generic web infrastructure, along with basic tooling, suggests a profit- or personally motivated actor rather than a state-aligned group. Indicators of compromise include the 15 IPs tied to the server21[.]org certificate, with key nodes at 185.221.239[.]162 (open directory) and 65.109.187[.]102 (Hetzner relay). Defenders are advised to monitor for unusual gcc usage, anomalous screen sessions, and high-concurrency SSH activity from these IPs.
INCIDENT DETAILS -
TYPE
BotnetDDoSCensorship Bypass
MOTIVATION
Financial gainPersonal gain
IMPACT
Censorship-bypass relaySSH botnet infrastructureOperational Impact: DDoS attacks on targeted servers
DATA BREACH
.bash_historyMHDDOS installerC-based flood toolsBotnet components
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for HFO ?
?
What was HFO's A.I Rankiteo Cyber Score in June 2026 ?
?
What was HFO's A.I Rankiteo Cyber Score in May 2026 ?
?
What was HFO's A.I Rankiteo Cyber Score in April 2026 ?
?
What was HFO's A.I Rankiteo Cyber Score in March 2026 ?
?
What was HFO's A.I Rankiteo Cyber Score in February 2026 ?
?
What was HFO's A.I Rankiteo Cyber Score in January 2026 ?
?
What was HFO's A.I Rankiteo Cyber Score in December 2025 ?
?
What was HFO's A.I Rankiteo Cyber Score in November 2025 ?
?
What was HFO's A.I Rankiteo Cyber Score in October 2025 ?
?
What was HFO's A.I Rankiteo Cyber Score in September 2025 ?
?
What was HFO's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on HFO's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with HFO ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view HFO's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?