## IP Intelligence Briefing: 104.21.25.131/32
Classification: LOW RISK β LEGITIMATE CDN INFRASTRUCTURE
Report Date: 2026-06-25
Executive Summary
IP address 104.21.25.131 belongs to Cloudflare, Inc. (ASN 13335) and operates as a legitimate Content Delivery Network (CDN) service. The address presents a low risk profile with no active threat indicators. This is a standard web server endpoint within Cloudflare's CDN infrastructure.
Profile Analysis
| Attribute | Value |
|---|---|
| Risk Score | 30 (Low Risk) |
| Organization | Cloudflare, Inc. |
| ASN | 13335 |
| Country | United States |
| Infrastructure Type | CDN |
| Reputation | Low Risk |
| Blacklist Count | 0 |
Network Services:
- Port 80 (HTTP)
- Port 443 (HTTPS)
- Port 8080 (HTTP-Alt)
- Port 8443 (HTTPS-Alt)
- Server Banner: Cloudflare
Threat Assessment
- Threat Indicators: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Malware Campaigns: None correlated
- DNSBL Listings: 1/8 lists (likely CDN-related)
- Persistently Malicious: False
Geolocation Validation
The IP resolves to United States with geolocation validation showing a plausible discrepancy. This is consistent with CDN routing behavior where origin servers may be geographically distributed. RTT measurements indicate 12ms average latency, consistent with regional US-based traffic patterns.
Historical Observations
Analysis of 20 historical observations reveals stable characteristics:
- ASN 13335 (CLOUDFLARENET) consistently identified
- Subnet 104.21.25.131/24 classified as "clean" with 0 abuse density
- No ownership changes or threat persistence detected
- Recent observations confirm standard CDN operation
Relationship Mapping
All detected relationships map to CLOUDFLARENET network infrastructure. No anomalous associations with malicious entities, domains, or certificates were identified.
Neighborhood Analysis
Subnet 104.21.25.131/24 shows:
- Abuse density: 0
- Classification: Clean
- Threat siblings: 0
- Active siblings: 1
Recommended Actions
No blocking or filtering required. This IP represents legitimate CDN infrastructure. Standard network policies should apply:
- Allow HTTPS (443) and HTTP (80) traffic as per organizational policy
- No firewall rules recommended
- No WAF configuration required beyond standard CDN rules
Intelligence Conclusion
104.21.25.131 is a standard, operational Cloudflare CDN endpoint. No defensive action is warranted. SOC analysts should treat this as legitimate infrastructure traffic. Any anomalies should be evaluated in context of expected CDN behavior patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cloudflare, Inc. |
| ASN | AS13335 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 8080 | http-alt | tcp | β |
| 8443 | https-alt | tcp | β |
| Closed Ports | 22, 25, 3389 (4 open / 7 scanned) | ||
| Server | cloudflare |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 5 |
| routing | 44% | 1 | 9 |
| services | 25% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 26% | 2 | 3 |
| Overall | 30% | 10 | 26 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-08 11:43:57 UTC |
| Last Seen | 2026-06-27 13:27:23 UTC |
| Profile Built | 2026-06-28 07:32:51 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 33 |
Full dossier details are available via our API.