# IP INTELLIGENCE BRIEFING: 135.225.93.215/32
Date: 2026-07-30
Classification: Cloud Infrastructure IP
Risk Level: Moderate (40/100)
---
## EXECUTIVE SUMMARY
IP 135.225.93.215 is Microsoft Azure cloud compute infrastructure located in Stockholm, Sweden (ASN 8075). The address shows no malicious threat indicators but registers as moderate risk due to DNSBL listings and control plane anomalies. The IP belongs to a clean subnet with zero abuse density.
---
## NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| **IP Address** | 135.225.93.215/32 |
| **Organization** | Divya Quamara (Microsoft Azure) |
| **ASN** | 8075 |
| **CIDR Block** | 135.225.0.0/16 |
| **Geolocation** | Stockholm, SE (59.33°N, 18.07°E) |
| **Infrastructure Type** | CloudCompute |
| **Provider** | Microsoft Azure |
---
## THREAT ASSESSMENT
Threat Indicators: None detected
Blacklist Status: 2 of 8 DNSBL listings (operatorScore: 0.1304)
Known Campaigns: None
Tor Exit: No
Known Attacker: No
Spam Source: No
Risk Breakdown:
- Risk Score: 40/100 (Moderate)
- Provider Score: 0
- Authority Score: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
---
## OBSERVATION HISTORY
Sixteen signals observed since 2026-07-30. Historical data indicates:
- Consistent cloud infrastructure classification
- Stable ownership (0 ownership changes)
- No persistent malicious behavior detected
- Geo-location signals: Stockholm, SE (AB region) and Redmond, WA (postal: 98052)
---
## NETWORK CONTEXT
Subnet Analysis (135.225.93.215/24):
- Abuse Density: 0 (Clean)
- Threat Siblings: 0
- Active Siblings: 1
- Classification: Clean
Control Plane Anomalies:
- Route Stability: False (isRouteStable)
- BGP Prefix: 135.224.0.0/15
- Route Changes (30d): 0
- DNSBL Listed: 2 of 8 total
---
## TECHNICAL PROFILE
DNS: No PTR records, no forward resolution (typical for cloud infrastructure)
Services: No open ports detected ("Firewalled / No Services")
Email: No SPF/DMARC records
Certificates: None detected
Behavioral:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
---
## SOC RECOMMENDATIONS
IMMEDIATE ACTION:
- Do not block this IP without further investigation. This is legitimate Microsoft Azure cloud infrastructure.
- The moderate risk score (40) appears to be a false positive related to DNSBL listings, not malicious activity.
- Review why traffic from this IP is being flagged in your environment.
IF BLOCKED BY YOUR ENVIRONMENT:
Implement the following rules to block if necessary:
```bash
# iptables
iptables -A INPUT -s 135.225.93.215 -j DROP
# nftables
nft add rule inet filter input ip saddr 135.225.93.215 drop
# pfSense
135.225.93.215/32
# Cloudflare WAF
ip.src eq 135.225.93.215 β BLOCK
```
INVESTIGATION PRIORITY: LOW
This IP represents cloud provider infrastructure, not end-user traffic. Legitimate Azure services may originate from this address.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 135.225.0.0/16 |
| RIR | ARIN |
| Country | SE |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 2 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-24 20:33:33 UTC |
| Last Seen | 2026-08-12 18:52:12 UTC |
| Profile Built | 2026-08-12 19:02:34 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.