# IP Intelligence Briefing: 135.232.201.224/32
Date: 2026-06-15
IP Address: 135.232.201.224/32
Risk Classification: Moderate Risk (Score: 40)
Infrastructure Type: Microsoft Azure Cloud Compute
---
## Executive Summary
IP 135.232.201.224 is a Microsoft Azure cloud infrastructure address with a moderate risk profile (40/100). The IP operates within the 135.232.0.0/14 BGP prefix under ASN 8075 and is geolocated to Chicago, IL, US. While the IP shows no active threat indicators or known campaign associations, it is listed on 2 of 8 DNSBLs. The subnet exhibits a 25% abuse density with one threat-sibling IP, warranting continued monitoring.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **ASN** | 8075 (Microsoft Azure) |
| **Location** | Chicago, IL, US (41.88, -87.63) |
| **Infrastructure** | Cloud Compute (Azure) |
| **DNSBL Listed** | 2/8 lists |
| **Control Plane** | Origin ASN 8075, Route Stable: No |
| **Services** | None detected (firewalled) |
| **Open Ports** | None |
---
## Threat Assessment
Current Indicators:
- No known attacker reputation
- Not a Tor exit node or proxy
- No spam source classification
- No active threat campaigns associated
- Abuse confidence score: Null
DNSBL Status:
The IP is enumerated on 2 DNS blacklist entries, contributing to its moderate risk rating.
---
## Neighborhood Analysis (135.232.201.0/24)
| Metric | Value |
|---|---|
| Subnet Abuse Density | 25% |
| Total Siblings | 4 |
| Active Siblings | 2 |
| Threat Siblings | 1 |
| Classification | Mostly Clean |
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 1 (135.232.201.42, Score: 50)
- Low Risk: 2 (135.232.201.67 & 135.232.201.230, Score: 25)
---
## Observation History
18 signals observed since 2026-06-08. Key observations include:
- Recent subnet-level classification: Mostly clean with inherited risk 2
- Operator score: 0.1304 (Minimal)
- Multiple signal dimensions covered (threat, routing, services, ownership, reputation, geolocation)
- Port scan performed on 2026-06-08 with no services detected
No persistent malicious behavior detected across the observation window.
---
## Security Recommendations
Recommended Actions:
- Monitor for service enumeration attempts
- Track DNSBL additions/removals
- Correlate with neighboring IP 135.232.201.42 (medium risk)
Firewall Rule Examples:
- iptables: `iptables -A INPUT -s 135.232.201.224 -j DROP`
- Cloudflare WAF: Block with expression `ip.src eq 135.232.201.224`
Note: Recommendations are probabilistic and should be combined with additional contextual signals before enforcement.
---
## Intelligence Conclusion
This Microsoft Azure IP presents moderate risk primarily due to DNSBL listings. The cloud infrastructure environment and lack of detected services reduce immediate threat concern, but the 25% subnet abuse density warrants continued monitoring. No immediate blocking is required, though defensive measures should be maintained for this subnet range.
Priority: Monitor
Action Level: Low
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 15:37:51 UTC |
| Last Seen | 2026-06-28 08:58:27 UTC |
| Profile Built | 2026-06-29 03:03:41 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 21 |
Full dossier details are available via our API.