# IP INTELLIGENCE BRIEFING: 162.158.211.11/32
Classification: Cloudflare CDN Edge Infrastructure
Risk Assessment: LOW RISK (Score: 25/100)
Report Date: Current Analysis Period
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
Target IP 162.158.211.11 is identified as a Cloudflare CDN edge endpoint belonging to ASN 13335 (Cloudflare, Inc.). The IP exhibits stable infrastructure behavior with no active threat indicators, blacklist listings, or malicious campaign associations. Observed risk score of 25 indicates minimal threat profile consistent with legitimate CDN infrastructure.
---
## INFRASTRUCTURE PROFILE
Ownership & Routing:
- Organization: Cloudflare, Inc.
- ASN: 13335
- BGP Prefix: 162.158.208.0/22
- RIR: ARIN
Geolocation:
- Country: United States (US)
- Region: Sofia-Capital (edge location designation)
- RTT Metrics: Avg 125.8ms, Min 119ms
- GeoValidation: Plausible (5 probes, 1650.3km distance)
Infrastructure Type: Content Delivery Network (CDN)
- Connection Type: Firewalled / No Services
- Anycast: Operational
- DNSSEC: Valid
---
## THREAT INDICATORS
Current Risk Signals:
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None
Control Plane:
- DNSBL Lists: 1 listing (likely false positive for CDN infrastructure)
- Operator Score: 0.1304 (Minimal)
- Route Stability: Stable
- IRR Consistency: Verified
---
## NETWORK NEIGHBORHOOD
Subnet Analysis: 162.158.211.0/24
- Abuse Density: 0%
- Classification: Mostly Clean
- Total Siblings: 4
Neighbor Risk Distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 162.158.211.12 | 25 | 85 |
| 162.158.211.17 | 25 | 85 |
| 162.158.211.27 | 25 | 85 |
| 162.158.211.28 | 25 | 85 |
All neighbors exhibit identical low-risk profiles, confirming legitimate CDN infrastructure deployment.
---
## OBSERVATION HISTORY
Monitoring Period: 21 observations
- Risk Score Trend: Stable at 25
- Infrastructure Classification: Consistently CDN
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: No
Recent Signals (2026-06-27):
- CDN Status: Active (Confidence: 90%)
- Operator Score: Minimal (Confidence: 30%)
- Overall Data Sufficiency: Complete (6/6 dimensions covered)
---
## NETWORK SERVICES
Open Ports: None detected
TLS Certificates: None
HTTP Services: None
Server Banners: None
This is expected behavior for CDN edge infrastructure that terminates traffic at the edge without exposing backend services.
---
## RELATIONSHIP GRAPH
Connected Entities:
- Primary Network: CLOUDFLARENET (20 connections)
- All relationships confirm Cloudflare infrastructure ownership
- No connections to external threat actors or suspicious networks
---
## RECOMMENDED ACTIONS
Immediate Actions: NO ACTION REQUIRED
Firewall Rules: Not applicable for CDN edge infrastructure
Monitoring Recommendations:
- Monitor for any sudden risk score increases
- Track for DNSBL listing changes
- Verify continued CDN behavior in observation history
- No blocking or rate limiting required for this IP
Context: This IP represents legitimate Cloudflare CDN infrastructure. Traffic to/from this address should be treated as expected internet traffic. No defensive blocking is recommended.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cloudflare, Inc. |
| ASN | AS13335 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-13 06:37:17 UTC |
| Last Seen | 2026-06-27 22:42:08 UTC |
| Profile Built | 2026-06-28 22:47:05 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.