# Intelligence Briefing: 104.22.56.26/32
Classification: LOW RISK β CDN Infrastructure
Date: 2026-06-20
Analyst: IPDebrief SOC Intelligence
---
## Executive Summary
IP 104.22.56.26 is a Cloudflare, Inc. CDN endpoint (ASN 13335) operating with a low-risk profile. No active threat indicators or malicious behavior detected. The IP represents legitimate cloud infrastructure with stable routing and minimal abuse exposure.
---
## Risk Assessment
| Metric | Value |
|---|---|
| **Risk Score** | 25 (Low) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Abuse Confidence** | Not applicable |
| **Reputation** | Low Risk |
| **Operator Score** | 0.1304 (Minimal) |
---
## Infrastructure Profile
Ownership: Cloudflare, Inc. (ASN 13335)
Network Role: Content Delivery Network (CDN)
Infrastructure Type: CDN
Geolocation: United States (Atlanta, GA)
CIDR Block: 104.22.56.0/24
BGP Prefix: 104.22.56.0/24
Route Stability: Stable (0 route changes in 30 days)
RPKI State: Unknown
DNS & Email:
- DNSSEC Valid: Yes
- DNSBL Listings: 1 of 8 (minor exposure)
- SPF/DMARC: Not configured
- PTR Records: None detected
Services:
- Open Ports: None detected
- TLS Certificates: None exposed
- HTTP Services: None active
---
## Threat Indicators
Active Threat Signals: None
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Active Threat Feeds: Empty
- Blacklist Count: 0
- Known Campaigns: None
DNSBL Exposure: 1 listing (minimal impact on 8 total lists)
---
## Neighborhood Analysis
Subnet: 104.22.56.0/24
Abuse Density: Low
Classification: Mostly Clean
Threat Siblings: 1 detected
Active Siblings: 0
Neighbor Count: 0
The immediate /24 neighborhood shows minimal abuse density, consistent with Cloudflare's infrastructure operations.
---
## Relationship Graph
Primary Associations:
- Multiple relationships to CLOUDFLARENET network
- 38 total relationship nodes identified
- All relationships indicate network-level cloud infrastructure
---
## Historical Observations
Total Signals Observed: 26
Observation Period: Recent (2026-06-20)
Key Signals:
- Port scans detected (no open ports confirmed)
- RTT geolocation discrepancies noted (claimed Atlanta, actual RTT suggests different origin)
- Operator risk assessment: Minimal (0.1304)
- No persistent malicious behavior detected
- No ownership changes observed
Geolocation Validation:
- RTT violation flagged: 38ms RTT below minimum possible 143.3ms for 7165km distance
- GeoPlausibility: False
- Multiple geo sources indicate US positioning
---
## Recommended Actions
Firewall Rules: None required
Threat Mitigation: No action needed
Monitoring: Standard CDN traffic monitoring sufficient
Actionable Intelligence:
1. No blocking recommended β legitimate CDN infrastructure
2. No port-level restrictions needed
3. Standard Cloudflare CDN traffic handling applies
4. Monitor for any changes in threat indicators
---
## SOC Analyst Notes
This IP represents standard Cloudflare CDN infrastructure with no evidence of malicious activity. The low risk score (25), absence of open services, and established network role indicate legitimate cloud operations. The single DNSBL listing likely reflects normal CDN blocking practices for abusive traffic rather than IP compromise.
Threat Confidence: Low β Standard Cloudflare endpoint
Action Priority: Routine monitoring only
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cloudflare, Inc. |
| ASN | AS13335 |
| Network Name | β |
| CIDR Block | 104.22.56.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 24% | 4 | 5 |
| services | 15% | 2 | 2 |
| ownership | 22% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 14 | 21 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-17 15:51:26 UTC |
| Last Seen | 2026-06-28 05:40:38 UTC |
| Profile Built | 2026-06-28 23:46:32 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 31 |
Full dossier details are available via our API.