# IP Intelligence Briefing: 13.67.236.135/32
## Executive Summary
IP address 13.67.236.135 is a Microsoft Azure cloud infrastructure endpoint located in Des Moines, Iowa. The IP exhibits moderate risk (Score: 50) primarily due to DNSBL listings and open SSH service. No active threat indicators detected. Infrastructure appears legitimate but warrants monitoring due to cloud hosting nature.
---
## Profile Overview
Ownership & Classification:
- Organization: Microsoft Corporation (ASN 8075)
- Network Role: CloudCompute infrastructure (Microsoft Azure)
- Geolocation: Des Moines, IA, US (Americas/Chicago timezone)
- BGP Prefix: 13.64.0.0/11
- Infrastructure Type: Cloud hosting environment
Risk Assessment:
- Overall Risk Score: 50 (Moderate)
- DNSBL Status: Listed on 2 of 8 threat feeds
- Threat Indicators: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
---
## Network Environment
Subnet Analysis (13.67.236.0/24):
- Abuse Density: 0% (Clean classification)
- Neighbor IP Count: 0
- Threat Siblings: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
The IP operates in isolation within its /24 subnet with no neighboring threats observed.
Associated Network: MSFT (Microsoft) - 29 relationship entries confirm infrastructure association with Microsoft ecosystem.
---
## Technical Services
Open Ports:
- Port 22/TCP: SSH (OpenSSH 7.6p1 Ubuntu-4ubuntu0.7)
DNS Status:
- Forward Resolution: Not confirmed
- PTR Hostnames: None
- Hosted Domains: 0
Control Plane:
- Origin ASN: 8075 (Microsoft)
- Route Stability: Not stable
- RPKI State: Unknown
- DNSSEC Valid: Yes
---
## Observation History (23 Observations)
Recent activity indicates:
- June 17, 2026: DNSBL listing activity detected (8 total lists, 2 listed)
- June 13, 2026: Geolocation confirmation - Des Moines, IA
- Infrastructure Classification: Consistently identified as Microsoft Azure cloud environment
No persistent malicious behavior observed. Threat persistence days: 0.
---
## Threat Indicators
- Campaign Correlation: None
- Certificate Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
- Blacklist Count: 0 (traditional blacklists)
---
## Recommended Actions
Based on risk profile, consider the following defensive measures:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 13.67.236.135 -j DROP
# nftables
nft add rule inet filter input ip saddr 13.67.236.135 drop
# Cloudflare WAF
ip.src eq 13.67.236.135
# AWS WAF
Addresses: 13.67.236.135/32
```
Note: These recommendations are probabilistic and should be combined with other signals before taking action. The moderate risk score warrants consideration, though legitimate Microsoft Azure infrastructure may be blocked inadvertently.
---
## Intelligence Assessment
The IP 13.67.236.135 represents legitimate Microsoft Azure cloud infrastructure. The moderate risk classification stems from:
1. DNSBL listings (2/8 feeds)
2. Open SSH service (common in cloud environments)
3. Cloud hosting classification
Recommendation: Monitor for behavioral anomalies rather than default block. If traffic is unexpected, verify against known Microsoft Azure IP ranges before taking action. The IP shows no evidence of malicious activity and operates within Microsoft's controlled infrastructure.
Classification: LOW THREAT - Cloud Infrastructure
Action Required: MONITOR
Priority: LOW
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:39 UTC |
| Last Seen | 2026-06-26 22:12:33 UTC |
| Profile Built | 2026-06-27 18:25:49 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.