IP Intelligence Briefing: 104.28.162.57
Date: 2026-06-08
---
**1. Core Profile**
- Risk Score: 70 (High Risk)
- Owner: Cloudflare, Inc. (ASN 13335)
- Geolocation: Germany (Hesse, Dreieich)
- Network Role: Firewalled / No Services (CDN infrastructure)
- Threat Indicators: No active malicious indicators, but listed on 4 DNSBLs (DNS-Based Blackhole List).
---
**2. Historical Observations**
- Recent Activity:
- DNSBL listings (8 total lists) detected on 2026-06-08.
- CDN infrastructure classification confirmed.
- No significant changes in risk scores or threat signals over the past 30 days.
- Stability: Subnet (104.28.162.0/24) shows low abuse density (0%), but route stability is unstable.
---
**3. Network Relationships**
- Linked Entities:
- Part of CloudflareNET (CLOUDFLARENET) subnet.
- No direct ties to known malicious organizations or campaigns.
- Services: No open ports or TLS services detected.
---
**4. Neighborhood Analysis**
- Subnet: 104.28.162.0/24 (23 IPs total).
- Risk Distribution:
- 19 IPs with low risk (avg. 40).
- 4 IPs with medium risk (avg. 65).
- Notable Neighbors:
- 104.28.162.7 (risk 65), 104.28.162.47 (risk 65), 104.28.162.78 (risk 50).
---
**5. Actionable Insights**
- Threat Context: While the IP is part of a legitimate CDN, DNSBL listings suggest potential misuse. Monitor for unexpected traffic patterns or DNS anomalies.
- Mitigation:
- Block DNSBL-listed IPs in your network perimeter.
- Consider whitelisting Cloudflare infrastructure if itβs a known provider.
- Validate geolocation data against internal threat feeds.
- Further Investigation: Check if neighboring IPs (e.g., 104.28.162.7, 104.28.162.47) show similar risks.
---
Summary: This IP is part of Cloudflareβs infrastructure in Germany but has historical DNSBL associations. No active threats detected, but its high risk score warrants monitoring. Use subnet-level analysis to assess broader network exposure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cloudflare, Inc. |
| ASN | AS13335 |
| Network Name | CLOUDFLARENET |
| CIDR Block | 104.16.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 15% | 6 | 7 |
| Data Coherence | Mostly Consistent (85%) β 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 21:38:41 UTC |
| Last Seen | 2026-06-08 21:48:51 UTC |
| Profile Built | 2026-06-05 05:11:24 UTC |
| Data Freshness | Live |
| Signal Types | 9 |
| Total Observations | 9 |
Full dossier details are available via our API.