Threat Intelligence Briefing: IP 104.28.165.54/32
Entity Information:
- IP Address: 104.28.165.54/32
- Provider: Cloudflare, Inc.
- ASN: 13335
- Location: United States
Observation History:
104.28.165.54/32 is part of Cloudflare's infrastructure, specifically used as a Content Delivery Network (CDN) endpoint. Historical data indicates that this IP has been involved in legitimate content delivery and security services. It primarily serves as a reverse proxy, ensuring the security and performance of websites hosted on Cloudflare's network.
Relationships:
- Parent Organization: Cloudflare, Inc.
- Associated Domains: The IP has been observed serving numerous domains under Cloudflare's umbrella. These domains benefit from Cloudflare's DDoS mitigation, Web Application Firewall (WAF), and secure content delivery services.
- Service Offerings: The IP is associated with services including DDoS protection, DNS services, and secure content delivery.
Neighborhood Data:
- Peering Relationships: The IP is part of a network with extensive peering arrangements, reflecting Cloudflare's global presence and infrastructure.
- Co-location: This IP shares infrastructure with other Cloudflare IPs, indicative of its role within a data center environment.
- Geolocation: The IP is geolocated within the United States, consistent with Cloudflare's data center locations.
Threat Intelligence Narrative:
104.28.165.54/32 is a legitimate IP address owned by Cloudflare, Inc., functioning as a CDN endpoint. Its primary role is to enhance the security, performance, and reliability of websites utilizing Cloudflare's services. The IP has not been associated with malicious activity in the observed data. Instead, it supports legitimate operations, including DDoS mitigation and secure content delivery.
Actionable Insights for SOC Analysts:
- Monitoring: Continue to monitor network traffic associated with this IP for any anomalies, given its legitimate use case.
- Whitelist: Consider whitelisting this IP in security devices to prevent false positives, as it is part of a trusted CDN provider.
- Threat Context: Be aware that any observed malicious activity from this IP could indicate IP spoofing or misuse, necessitating further investigation.
This briefing provides a comprehensive overview of IP 104.28.165.54/32, emphasizing its legitimate use within Cloudflare's infrastructure. SOC teams should leverage this information to inform their network security strategies and ensure accurate threat detection and response.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cloudflare, Inc. |
| ASN | AS13335 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 10 | 15 |
| Data Coherence | Mostly Consistent (85%) β 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-08 05:01:27 UTC |
| Last Seen | 2026-06-25 01:40:14 UTC |
| Profile Built | 2026-06-25 01:45:09 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.