104.18.21.210 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 104.18.21.210 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Possibly Malicious Host 🟢 10/100
Host and Network Information
- View other sources: Spamhaus VirusTotal
- Country:
- Network:
- Noticed: 1 times
- Protocols Attacked: Anonymous Proxy
- Passive DNS Results: btb4qa450.com otopad.xyz preferredptkc.com memadefashion.com june.technology www.memadefashion.com www.fmb.com fmb.com get.foxglove.dev docs.foxglove.dev www.june.technology www.nsnews.com lgsamx.com subscription.nsnews.com northdallasimports.com truxmobile.gflenv.com de-ie-cer-sc-26681-remove-price-override.socrates.ssdgws.co.uk app.foxglove.dev www.711.nl nsnews.com sa.foxglove.dev metricsv2.rfidtools.decathlon.net stageaemapi.transunion.com trustedrealty.com qa-fi-u17-fbmvp-19538-firedpdforexperime.az.ssdgws.co.uk actuate.foxglove.dev raamdecoratievantuiss.nl foxglove.dev 25phlove.com wjtwo66.com stagingholman.com api-docs.foxglove.dev keycloak.autodoc.dev www.juvederm.fi wt.plf-test-replicas-1.auth0c.com edge.tenants.plf-test-replicas-1.auth0c.com plf-test-replicas-1.auth0c.com wt.test-azure-lively-mouse-4158.auth0c.com edge.tenants.test-azure-lively-mouse-4158.auth0c.com test-azure-lively-mouse-4158.auth0c.com jhmson.com keovip8.tv qa-nl-una-fixdsi-2661-wrapperrelease.az.ssdgws.co.uk hub.propellerhealth.onl monitor1.franklymedia.com www.berkleyoffshore.com berkleyoffshore.com ronspillguide.com mahindraespares.com qa-au-7fr-fixfbmvp-10961-alternativestor.az.ssdgws.co.uk magic.staginghiiv.com epi-int.peppergreece.com qa-gb-qmx-ecrp-8909-cmsmaintenancepage.az.ssdgws.co.uk f456h.com patient.propellerhealth.onl helloprivacy.com dev.helloprivacy.com thatek.com citruspensions.co.uk staging.helloprivacy.com lgnem.brezan.nl evilminion.tk replit2.evilminion.tk www.argonmoto.com.cdn.cloudflare.net www.beehiiv.dev prestashopcheckout.com testpublication.andrewplatkin.com cm.711.nl cm-client.711.nl 711.nl ims-insulation.co.uk merchantcp.co.uk azdemo-uk.propellerhealth.onl provider-demo.propellerhealth.onl spp.propellerhealth.onl api.propellerhealth.onl provider.propellerhealth.onl internalpropeller.propellerhealth.onl login.propellerhealth.onl console-dev.foxglove.dev api-dev.foxglove.dev ccbm.bdhn-prod.cc-bm.net.cdn.cloudflare.net d19390f82d45d1ab23a1db23d3350a39cd93dc2d.vercel-workers.com newsletter.hurd.dev staginghiiv.com api.foxglove.dev console.foxglove.dev sandbox.martinelli.dev kpwtec.com epi-prod.peppergreece.com www.peppergreece.com newsletter.blendwith.us www.hurd.dev embeds.staginghiiv.com publication.hurd.dev fitsgr8.com reminded.org www.my-exclusive.com padl.et fundacja.veolia.pl www.fundacja.veolia.pl www.veolia.pl www.foundersmentality.com preprod.foundersmentality.com 4hujj18.com www.argonmoto.com campaign.nyxcosmetics.co.uk nojuice.ag cfpages.martinelli.dev www.grantthornton.cm martinelli.dev my-exclusive.com 4hua98.com www-cdn.capitaliq.com.cdn.cloudflare.net rd.capitaliq.com.cdn.cloudflare.net betboo15.com ice-casino.net www.fundacja.veolia.pl.cdn.cloudflare.net preprod.foundersmentality.com.cdn.cloudflare.net www.capitaliq.com.cdn.cloudflare.net 971ii.com loreal.co.id 2456qu.com kerastase.pe h5.bitget.com.cdn.cloudflare.net pzfyzf4.yizhipay.pro.cdn.cloudflare.net pzfyzf2.yizhipay.pro.cdn.cloudflare.net www.grantthornton.cm.cdn.cloudflare.net www.veolia.pl.cdn.cloudflare.net www.foundersmentality.com.cdn.cloudflare.net vulkanbet-ru.partners doudounemonclers-pascher.com www.driftingfans.com.cdn.cloudflare.net
Open Ports Detected
2052 2053 2082 2083 2086 2087 443 80 8080 8443 8880
Map
Whois Information
- NetRange: 104.16.0.0 - 104.31.255.255
- CIDR: 104.16.0.0/12
- NetName: CLOUDFLARENET
- NetHandle: NET-104-16-0-0-1
- Parent: NET104 (NET-104-0-0-0-0)
- NetType: Direct Allocation
- OriginAS: AS13335
- Organization: Cloudflare, Inc. (CLOUD14)
- RegDate: 2014-03-28
- Updated: 2024-09-04
- Comment: All Cloudflare abuse reporting can be done via https://www.cloudflare.com/abuse
- Comment: Geofeed: https://api.cloudflare.com/local-ip-ranges.csv
- Ref: https://rdap.arin.net/registry/ip/104.16.0.0
- OrgName: Cloudflare, Inc.
- OrgId: CLOUD14
- Address: 101 Townsend Street
- City: San Francisco
- StateProv: CA
- PostalCode: 94107
- Country: US
- RegDate: 2010-07-09
- Updated: 2024-11-25
- Ref: https://rdap.arin.net/registry/entity/CLOUD14
- OrgNOCHandle: CLOUD146-ARIN
- OrgNOCName: Cloudflare-NOC
- OrgNOCPhone: +1-650-319-8930
- OrgNOCEmail: noc@cloudflare.com
- OrgNOCRef: https://rdap.arin.net/registry/entity/CLOUD146-ARIN
- OrgAbuseHandle: ABUSE2916-ARIN
- OrgAbuseName: Abuse
- OrgAbusePhone: +1-650-319-8930
- OrgAbuseEmail: abuse@cloudflare.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE2916-ARIN
- OrgRoutingHandle: CLOUD146-ARIN
- OrgRoutingName: Cloudflare-NOC
- OrgRoutingPhone: +1-650-319-8930
- OrgRoutingEmail: noc@cloudflare.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/CLOUD146-ARIN
- OrgTechHandle: ADMIN2521-ARIN
- OrgTechName: Admin
- OrgTechPhone: +1-650-319-8930
- OrgTechEmail: rir@cloudflare.com
- OrgTechRef: https://rdap.arin.net/registry/entity/ADMIN2521-ARIN
- RNOCHandle: NOC11962-ARIN
- RNOCName: NOC
- RNOCPhone: +1-650-319-8930
- RNOCEmail: noc@cloudflare.com
- RNOCRef: https://rdap.arin.net/registry/entity/NOC11962-ARIN
- RAbuseHandle: ABUSE2916-ARIN
- RAbuseName: Abuse
- RAbusePhone: +1-650-319-8930
- RAbuseEmail: abuse@cloudflare.com
- RAbuseRef: https://rdap.arin.net/registry/entity/ABUSE2916-ARIN
- RTechHandle: ADMIN2521-ARIN
- RTechName: Admin
- RTechPhone: +1-650-319-8930
- RTechEmail: rir@cloudflare.com
- RTechRef: https://rdap.arin.net/registry/entity/ADMIN2521-ARIN
Links to attack logs
anonymous-proxy-ip-list-2025-06-23 anonymous-proxy-ip-list-2025-06-22
Share on: