# IP Intelligence Briefing: 128.203.200.216
Date: 2026-07-30
Classification: LOW RISK
Status: Cloud Infrastructure - Microsoft Azure
## Executive Summary
IP address 128.203.200.216 is identified as Microsoft Azure cloud infrastructure with a low-risk profile. The IP resolves to stretchoid.com DNS records, a known Microsoft Azure naming convention. No active threat indicators or malicious activity were observed during the intelligence collection period.
## Technical Profile
Risk Assessment:
- Overall Risk Score: 25/100
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Classification: Low Risk
Ownership & Registration:
- ASN: 8075 (Microsoft Azure)
- Organization: Divya Quamara
- Network: 128.203.128.0/17
- RIR: ARIN
- Abuse Contact: Available via RDAP
Geolocation:
- Country: United States (US)
- Region: Massachusetts (US-MA)
- City: Boston
- Timezone: America/New_York
- Geo Validation: Consensus confirmed
Network Characteristics:
- Infrastructure Type: Cloud Compute
- Connection Type: Cloud
- Hosting: Yes
- CDN/VPN/Proxy: No
- Anycast: No
## DNS & Resolution Analysis
Forward Resolution:
- Primary Hostname: azpdcg90igxg.stretchoid.com
- Forward Confirmed: Yes
- Resolution Count: 1
Email Authentication:
- SPF Record: Not configured
- DMARC Record: Not configured
- TXT Record Count: 0
DNSBL Status:
- Listed Count: 1 out of 8 total lists
- Overall DNSBL Status: Minimal listing
## Services & Ports
Open Ports: None detected
TLS Certificate: Not observed
HTTP Title: Not observed
Server Banner: Not observed
This IP is classified as "Firewalled / No Services" with no active service signatures detected.
## Threat Indicators
Malicious Activity:
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Threat Feeds: None
- Known Campaigns: None
Campaign Analysis:
- Campaign Likelihood: Not applicable
- CERT Matches: 0
- Correlated IPs: 0
Network Behavior:
- Threat Observation Count: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
## Temporal Analysis
Observation History:
- Total Observations: 17 signals recorded
- Recent Activity: 2026-07-30
- Ownership Changes: 0
- Threat Persistence: 0 days
The IP has demonstrated consistent ownership attribution with no malicious signal accumulation over the observation period.
## Neighborhood Analysis
Subnet Profile: 128.203.200.216/24
- Abuse Density: 0 (Clean)
- Classification: Clean
- Inherited Risk: 0
- Total Siblings: 3
- Active Siblings: 0
- Threat Siblings: 0
Neighbor IPs:
- 128.203.200.49: Risk Score 25, Authority Score 60
- 128.203.200.175: No scoring data available
The subnet shows minimal abuse activity with one sibling IP sharing similar risk characteristics.
## Relationships
DNS Associations:
- azpdcg90igxg.stretchoid.com (Multiple records)
Network Associations:
- cloud network (Multiple records)
Total relationships: 6 entities linked through DNS and network associations.
## Recommended Actions
Security Posture: No immediate action required
The IP exhibits characteristics of legitimate cloud infrastructure. Standard monitoring practices are recommended. No firewall rules or blocking actions are advised based on current risk assessment.
Monitoring Recommendations:
- Continue standard traffic monitoring
- No immediate blocking required
- Consider correlation with other cloud provider IPs in the same ASN
## Threat Intelligence Narrative
IP 128.203.200.216 represents Microsoft Azure cloud infrastructure operating within the 128.203.128.0/17 CIDR block. The IP maintains a low-risk profile with a risk score of 25, attributed to its classification as cloud hosting infrastructure rather than malicious activity. DNS resolution to stretchoid.com confirms Azure cloud service association. No open ports or active services were detected, indicating the IP may be used for internal routing or as a backend infrastructure component.
The IP shows no correlation with known threat campaigns, malware distribution networks, or spam operations. The 17 observed signals over the collection period demonstrate consistent ownership attribution to Microsoft Azure without escalation in threat indicators. Neighborhood analysis indicates the /24 subnet maintains a clean abuse density profile.
Final Assessment: This IP should be treated as benign cloud infrastructure. No defensive actions are recommended. SOC analysts may reference this IP as a known Microsoft Azure endpoint when evaluating related traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 128.203.128.0/17 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdcg90igxg.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdcg90igxg.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 08:44:40 UTC |
| Last Seen | 2026-08-12 19:21:51 UTC |
| Profile Built | 2026-08-12 19:40:05 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.