IPDEBRIEF INTELLIGENCE BRIEFING
Subject: 104.23.239.85/32
Classification: Low Risk
Date: Current
EXECUTIVE SUMMARY
The IP address 104.23.239.85 is a Cloudflare CDN endpoint with a risk score of 25. The IP demonstrated low-risk characteristics across all observed dimensions and exhibited no malicious threat indicators.
OWNERSHIP AND INFRASTRUCTURE
The IP belongs to Cloudflare, Inc. (ASN 13335) and operates as a Content Delivery Network (CDN) infrastructure component. Geolocation data placed the endpoint in Frankfurt am Main, Germany (US country code). The IP showed no characteristics of cloud-based, VPN, proxy, Tor, hosting, mobile, or residential services. The IP maintained a stable ownership profile with zero ownership changes observed.
THREAT INDICATORS
No threat indicators were detected. The IP showed:
- Zero blacklist entries
- Zero known attacker associations
- Zero spam source indicators
- No Tor exit node association
- No known campaign participation
- Zero threat observation count attributed to malicious activity
NETWORK BEHAVIOR
The IP presented as a firewalled endpoint with no open ports detected. DNSSEC validation was confirmed. No email authentication records (SPF, DMARC) were associated with the IP. The endpoint showed no WAF violations, honeypot hits, or enumeration strikes. Behavioral analysis indicated zero incidents with no auto-banning events.
NEIGHBORHOOD ANALYSIS
The /24 subnet (104.23.239.0/24) maintained an abuse density of 0.0 and classified as "mixed." Seven neighboring IPs were analyzed, all showing identical risk characteristics: risk score 25, authority score 85, and low risk classification. No high or medium risk neighbors were detected.
HISTORICAL OBSERVATIONS
Nineteen observations were recorded over the analysis period. Signals consistently identified the IP as Cloudflare CDN infrastructure with 90% confidence. Operator scoring maintained at 0.1304 (Minimal). Subnet abuse density remained stable at 0.5. No degradation or escalation in risk profile was observed.
RELATIONSHIPS
All sixteen detected relationships classified as "Same Network" type pointing to CLOUDFLARENET. No external network, organization, hostname, or certificate relationships were identified beyond the primary Cloudflare network.
CONTROL PLANE
Origin ASN 13335 with BGP prefix 104.23.239.0/24. Route stability evaluated as false. DNSBL listing count of 1 across 8 total lists. Operator score 0.1304 (Minimal). RIR registry ARIN.
RECOMMENDATIONS
The IP address 104.23.239.85 represents legitimate Cloudflare CDN infrastructure. No blocking or mitigation action is recommended. The endpoint exhibits standard CDN behavior with no malicious indicators. Allow traffic unless specific application-layer activity warrants additional investigation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cloudflare, Inc. |
| ASN | AS13335 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-18 03:21:21 UTC |
| Last Seen | 2026-06-28 05:58:02 UTC |
| Profile Built | 2026-06-29 00:02:41 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 21 |
Full dossier details are available via our API.