IPDebrief

104.23.239.84

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 104.23.239.84/32

Classification: Moderate Risk CDN Infrastructure

Date: Current Assessment

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP address 104.23.239.84 operates as Cloudflare CDN infrastructure with a moderate risk score of 40. The address belongs to the 104.23.239.0/24 subnet classified as high-abuse density, with 5 of 8 sibling IPs exhibiting threat indicators. No direct threat indicators detected on the target IP itself; risk stems from neighborhood context.

---

## Infrastructure Profile

Ownership: Cloudflare, Inc. (ASN 13335, ARIN)

Infrastructure Type: CDN (Content Delivery Network)

Network Role: Firewalled / No Services Detected

Geolocation: United States (Frankfurt am Main region)

Distance from Claimed Location: 296.5 km

Average RTT: 113.8 ms

The IP is part of Cloudflare's global edge network with anycast routing. No open ports or services were discovered; the address responds with firewalled responses typical of CDN edge nodes.

---

## Threat Assessment

Overall Risk Score: 40 (Moderate)

Abuse Confidence Score: Not applicable (infrastructure classification)

Blacklist Status: Clean (0 blacklist entries)

Threat Feeds: No matches

Known Campaigns: None identified

The target IP shows no direct threat indicators. It is not a Tor exit node, known attacker, or spam source. DNSSEC validation is confirmed active.

---

## Neighborhood Context Analysis

Subnet: 104.23.239.0/24

Abuse Density: 0.625 (High)

Inherited Risk Score: 12

Sibling IP Distribution:

The 104.23.239.0/24 subnet demonstrates consistent risk characteristics across all monitored addresses, indicating this is a well-known Cloudflare edge segment. The high abuse density classification reflects typical CDN traffic patterns rather than malicious activity.

---

## Historical Observation Trend

Total Observations: 18

Risk Persistence: 0 days (transient)

Ownership Changes: 0 (stable)

Key Historical Signals:

The IP has maintained consistent classification as Cloudflare CDN infrastructure across all observation windows with no degradation in risk posture.

---

## Network Relationships

All 13 relationship indicators confirm association with CLOUDFLARENET network. No connections to external malicious infrastructure, domains, or organizations were identified.

---

## Recommended Security Actions

Classification: Allow with Monitoring

1. Permit Traffic: As a legitimate CDN provider, allow traffic from this IP address.

2. Rate Limiting: Apply standard CDN rate limiting policies (100-500 requests/second) to mitigate potential abuse.

3. WAF Integration: If using Cloudflare WAF, ensure policies are configured for legitimate CDN traffic.

4. No Blocking: Do not blockβ€”this is infrastructure required for legitimate web traffic.

5. Monitor: Watch for unusual traffic patterns that deviate from expected CDN behavior.

---

## Conclusion

IP 104.23.239.84 is a Cloudflare CDN edge address with moderate risk classification primarily due to neighborhood context. No direct threat indicators are present. The IP should be permitted through security controls with standard CDN traffic management policies applied. No blocking or restrictive firewall rules are recommended.

---

Data Sources: IPDebrief Intelligence Platform

Classification: Defensive Security Intelligence

Status: Complete

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionHesse
CityFrankfurt am Main
Timezoneβ€”
Latitude50.12
Longitude8.68

🏒 Ownership & Registration

OrganizationCloudflare, Inc.
ASNAS13335
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CDN

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
23
routing
8%
11
services
8%
11
ownership
24%
23
reputation
31%
13
geolocation
27%
23
Overall21%914
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-18 03:21:21 UTC
Last Seen2026-06-28 05:57:32 UTC
Profile Built2026-06-29 00:02:41 UTC
Data FreshnessLive
Signal Types18
Total Observations21
πŸ” 18 signal types Β· 21 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.