Verdict
LIKELY BENIGNHigh confidence
4Supporting signals
4Independent sources
2Recent observations
5 / 100Threat score
Why the engine decided this
Deterministic engine · activity none- KNOWN_PUBLIC_DNS Indicator is a well-known public recursive DNS resolver.
- OTX_KNOWN_FALSE_POSITIVE AlienVault OTX marks the indicator as a known false positive or whitelisted.
- ABUSEIPDB_ALLOWLIST AbuseIPDB lists the IP on its allowlist.
- Cloudflare DNS public DNS resolver: abuse reports usually describe traffic relayed through the service.
Key indicators
- IP address
- 1.1.1.1
- ASN
- AS13335
- Holder
- CLOUDFLARENET - Cloudflare, Inc.
- Country
- Australia (AU)
- Network
- APNIC-LABS
- Prefix
- 1.1.1.0/24
- ISP
- APNIC and Cloudflare DNS Resolver project
- Usage
- Content Delivery Network
- Open ports
- 53, 80, 443, 2052, 2053, 2082, 2083, 2086, 2087, 8080, 8443, 8880
- Tor exit
- No
- First seen
- Not reported by any source
- Last seen
- 2026-09-23 (0 days before)
Relationship graph
Expand| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| IOCSCAPE knowledge base | Known public DNS resolver (Cloudflare DNS). | — | — | Benign |
| Allowlisted with 0% confidence despite 58 reports; report volume here is noise. | 0% | 0 days recent | Benign | |
| Marked as a known false positive or whitelisted. | — | — | Benign | |
| No vendor flags it (0 of 89). | 0/89 | 0 days recent | Benign | |
| Network APNIC-LABS (1.1.1.0 - 1.1.1.255), AU; APNICRANDNET Infrastructure Contact, IRT-APNICRANDNET-AU, APNIC Research and Development. | — | — | Context | |
| Announced in 1.1.1.0/24 by AS13335 (CLOUDFLARENET - Cloudflare, Inc.). | — | — | Context | |
| Open ports 53, 80, 443, 2052, 2053, 2082, 2083, 2086, 2087, 8080, 8443, 8880. | — | — | Context |
Coverage · checked, no record: ThreatFox, URLhaus, Feodo Tracker, Emerging Threats, Tor exit list · failed: GreyNoise
Analyst summary
Consistent with engineLikely benign: Cloudflare DNS is a public resolver. Allowlisted with 0% confidence despite 58 reports; report volume here is noise.
Why the evidence points to likely benign
- [AbuseIPDB] Allowlisted with 0% confidence despite 58 reports; report volume here is noise.
- [IOCSCAPE knowledge base] Known public DNS resolver (Cloudflare DNS).
- [AlienVault OTX] Marked as a known false positive or whitelisted.
- [VirusTotal] No vendor flags it (0 of 89).
Lookups failed for GreyNoise: no information either way.
Attribution
Operated by Cloudflare DNS; reports describe traffic relayed through the service, not the operator's own activity.
Written by rules from the engine's evidenceSuggested pivots
Threat context
Context onlyAll evidence
13 sources queried · click a row for its raw fields · ages computed by the engine| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| IOCSCAPE knowledge base | Known public DNS resolver (Cloudflare DNS). | — | — | Benign |
| Allowlisted with 0% confidence despite 58 reports; report volume here is noise. | 0% | 0 days recent | Benign | |
| Marked as a known false positive or whitelisted. | — | — | Benign | |
| No vendor flags it (0 of 89). | 0/89 | 0 days recent | Benign | |
| Network APNIC-LABS (1.1.1.0 - 1.1.1.255), AU; APNICRANDNET Infrastructure Contact, IRT-APNICRANDNET-AU, APNIC Research and Development. | — | — | Context | |
| Announced in 1.1.1.0/24 by AS13335 (CLOUDFLARENET - Cloudflare, Inc.). | — | — | Context | |
| Open ports 53, 80, 443, 2052, 2053, 2082, 2083, 2086, 2087, 8080, 8443, 8880. | — | — | Context | |
| Lookup failed: no information either way. | — | — | Failed | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record |
Engine rules applied
- LOOKUPS_FAILEDOne or more lookups failed; their absence carries no information.
- KNOWN_PUBLIC_DNSIndicator is a well-known public recursive DNS resolver.
- OTX_KNOWN_FALSE_POSITIVEAlienVault OTX marks the indicator as a known false positive or whitelisted.
- ABUSEIPDB_ALLOWLISTAbuseIPDB lists the IP on its allowlist.
- ABUSEIPDB_ZERO_CONFIDENCEAbuseIPDB reports exist but the abuse confidence score is 0%.
Engine notes
- Cloudflare DNS public DNS resolver: abuse reports usually describe traffic relayed through the service.
Analyst summary
Consistent with engineLikely benign: Cloudflare DNS is a public resolver. Allowlisted with 0% confidence despite 58 reports; report volume here is noise.
Why the evidence points to likely benign
- [AbuseIPDB] Allowlisted with 0% confidence despite 58 reports; report volume here is noise.
- [IOCSCAPE knowledge base] Known public DNS resolver (Cloudflare DNS).
- [AlienVault OTX] Marked as a known false positive or whitelisted.
- [VirusTotal] No vendor flags it (0 of 89).
Key indicators
- IP address
- 1.1.1.1
- ASN
- AS13335
- Holder
- CLOUDFLARENET - Cloudflare, Inc.
- Country
- Australia (AU)
- Network
- APNIC-LABS
- Prefix
- 1.1.1.0/24
- ISP
- APNIC and Cloudflare DNS Resolver project
- Usage
- Content Delivery Network
- Open ports
- 53, 80, 443, 2052, 2053, 2082, 2083, 2086, 2087, 8080, 8443, 8880
- Tor exit
- No
- First seen
- Not reported by any source
- Last seen
- 2026-09-23 (0 days before)
By source
Relationship graph
Click a node for details · edges are observed relationships, not ownershipContext
KNOWN_PUBLIC_DNS Indicator is a well-known public recursive DNS resolver.
Attribution
Operated by Cloudflare DNS; reports describe traffic relayed through the service, not the operator's own activity.
Relationship ≠ ownership. Shared IPs, ASNs or platforms never imply the same operator.
Threat context
Context onlyNo group is directly linked to this indicator by any source.
Evidence timeline
- 2026-09-23AbuseIPDB: Allowlisted with 0% confidence despite 58 reports
- 2026-09-23VirusTotal: No vendor flags it (0 of 89)
- 2026-09-23Investigated
Run history
2 collections of this indicator- 2026-09-26LIKELY BENIGN5Stored evidenceShown
- 2026-09-23LIKELY BENIGN5Live lookupsOpen
Sources are checked again on every live run, so a source that has since dropped the indicator from its feed can change the verdict. Each run keeps the evidence exactly as it was collected.
Recommended next steps
- contextInvestigate the internal host and the domains it queried, not the resolver.
- huntReview the specific traffic that triggered the alert.
Pivot to other tools
Opens the indicator in the source's own site (new tab).

