# IP Intelligence Briefing: 104.28.162.169/32
Classification: Low Risk โ Infrastructure/CDN
Date: 2026-07-30
Analyst: IPDebrief Intelligence
---
## Executive Summary
IP 104.28.162.169 presents as a low-risk infrastructure address with no active threat indicators. The address belongs to ASN 13335 (Cloudflare) and demonstrates no malicious behavior across all observation vectors. No security actions are recommended at this time.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 0 (Low Risk) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Origin ASN** | 13335 |
| **BGP Prefix** | 104.28.162.0/24 |
| **Network Role** | Firewalled / No Services |
| **DNSSEC Valid** | Yes |
| **Route Changes (30d)** | 0 |
Ownership & Geolocation:
- ASN 13335 (Cloudflare)
- Primary Geo: Portugal (PT), Montijo, Setúbal
- Secondary Geo Signals: US (39.83°N, -98.58°W) โ conflicting data
- Distance from primary geo: 1,943 km
- Validation Status: ICMP blocked โ unable to validate
---
## Threat Analysis
Threat Indicators
- Threat Indicators: None
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
- Known Campaigns: None
- Threat Feeds: None
- Is Known Attacker: False
- Is Spam Source: False
- Is Tor Exit: False
Network Behavior
- Open Ports: None detected
- Services: No open services
- TLS Certificate: None
- HTTP Title: None
- Server Banner: None
Control Plane
- Operator Score: 0.1304 (Minimal)
- DNSBL Listed: 0 of 8 total lists
- RPKI State: Not available
- IRR Consistency: Not available
- MOAS Status: False
---
## Historical Observation
Observation Count: 10 signals (most recent: 2026-07-30)
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Is Persistently Malicious: False
Signal Trends:
- Geo signals show conflicting country data (PT/US)
- Operator score labeled "Minimal" (0.1304)
- No persistent threat behavior detected
- Ports scanned with no active services discovered
---
## Neighborhood Analysis
Subnet: 104.28.162.0/24
Total Siblings: 57
Abuse Density: 3.5%
Risk Distribution:
- High Risk: 2 IPs
- Medium Risk: 30 IPs
- Low Risk: 25 IPs
Notable Neighbors:
- 104.28.162.2 โ Risk: 25, Authority: 85
- 104.28.162.7 โ Risk: 25, Authority: 85
- 104.28.162.8 โ Risk: 55, Authority: 85
- 104.28.162.9 โ Risk: 40, Authority: 85
Inherited Risk: 0
---
## Relationship Graph
Direct Relationships: None detected
---
## Campaign Correlation
- Campaign Likelihood: Not applicable
- Certificate Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
- Certificate Subjects: None
---
## Recommended Actions
No Actions Required. The IP presents as legitimate infrastructure with no threat indicators. Standard monitoring practices apply.
---
## Intelligence Assessment
IP 104.28.162.169 is classified as low-risk infrastructure. Key findings:
1. Clean Risk Profile: Zero risk score with no threat indicators
2. CDN/Cloud Infrastructure: Associated with Cloudflare (ASN 13335), consistent with edge caching/firewalling
3. No Service Exposure: No open ports or services detected
4. Subnet Context: 3.5% abuse density in /24 subnet; 2 high-risk siblings identified
5. Temporal Stability: No ownership
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Cloudflare, Inc. |
| ASN | AS13335 |
| Network Name | CLOUDFLARENET |
| CIDR Block | 104.16.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 22:21:30 UTC |
| Last Seen | 2026-07-30 18:36:17 UTC |
| Profile Built | 2026-07-30 18:54:00 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.