# IPDEBRIEF INTELLIGENCE BRIEFING
Subject: 158.158.36.150/32
Classification: Moderate Risk โ Cloud Infrastructure
Date: 2026-08-05
Analyst: IPDebrief Intelligence
---
## EXECUTIVE SUMMARY
IP 158.158.36.150 is a Microsoft Azure cloud compute address classified as moderate risk (score: 40) with no active threat indicators. The IP resides in Madrid, Spain, within the 158.158.0.0/16 Microsoft Azure block. No services are publicly accessible; the address is firewalled with no open ports detected.
---
## OWNERSHIP AND INFRASTRUCTURE
- ASN: 8075 (IRT-MICROSOFT-APNIC-SG)
- Organization: MICROSOFT-APNIC-AP
- CIDR Block: 158.158.0.0/16
- Infrastructure Type: CloudCompute (Microsoft Azure)
- Geolocation: Madrid, Spain (ES)
- Timezone: Europe/Madrid
---
## THREAT ASSESSMENT
- Overall Risk Score: 40 (Moderate)
- Provider Score: 0
- Authority Score: 0
- Blacklist Count: 0
- Abuse Confidence Score: Not reported
- Threat Indicators: None
- Known Campaigns: None
- Threat Feeds: None
Key Risk Factors:
- DNSBL listed on 2 of 8 monitored lists
- Operator score rated as "Minimal" (0.1304)
- Route stability flagged as false (potential routing inconsistency)
- No DNSSEC validation data
Mitigating Factors:
- No known attacker or spam source designation
- Not a Tor exit node or proxy
- No open services or ports detected
- No threat persistence observed
---
## NETWORK BEHAVIOR
- Open Ports: None
- TLS Certificate: Not detected
- HTTP Services: None
- PTR Resolution: Not confirmed
- Forward Hostnames: None
- Email Auth (SPF/DMARC): Not configured
- HSTS/CSP/HTTP2: Not detected
---
## SUBNET ANALYSIS
Subnet: 158.158.36.150/24
- Abuse Density: 0 (Clean)
- Classification: Clean
- Inherited Risk: 0
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
Network Classification: Microsoft Azure infrastructure with no neighboring abuse activity.
---
## OBSERVATION HISTORY
Total observations: 17
- Most Recent: 2026-08-05T19:01:04
- Threat Observation Count: 0
- Threat Persistence Days: 0
- Persistence Classification: Not persistently malicious
Recent signals indicate consistent clean classification with minimal operator scoring. No escalation in threat behavior detected over the observation window.
---
## RELATIONSHIP ANALYSIS
- Relationship Count: 6
- Relationship Type: Same Network (MICROSOFT-APNIC-AP)
- Related Entities: All point to Microsoft Azure infrastructure
---
## RECOMMENDED SECURITY ACTIONS
Risk-Based Recommendation: Block (Score: 40)
Firewall Rules:
- iptables: `iptables -A INPUT -s 158.158.36.150 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 158.158.36.150 drop`
- nginx: `deny 158.158.36.150;`
- pfSense: `158.158.36.150/32`
- Cloudflare WAF: Block with expression `ip.src eq 158.158.36.150`
- AWS WAF: `Addresses: ["158.158.36.150/32"]`
Note: These recommendations are probabilistic and should be combined with other signals before taking action.
---
## INTELLIGENCE NARRATIVE
IP 158.158.36.150 is a Microsoft Azure cloud compute address assigned to the 158.158.0.0/16 block, located in Madrid, Spain. The IP carries a moderate risk score of 40, primarily driven by DNSBL listings and routing inconsistencies rather than active threat indicators. No services are exposed, and the subnet shows zero abuse density with clean classification. Historical analysis indicates no persistent malicious behavior or threat persistence. The address is firewalled with no open ports or TLS certificates detected. While no immediate threat indicators exist, the moderate risk score and DNSBL presence warrant defensive blocking in perimeter security controls. This IP should be monitored for service activation or behavioral changes, as the current risk profile reflects a dormant cloud asset rather than an active threat source.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-MICROSOFT-APNIC-SG |
| ASN | AS8075 |
| Network Name | MICROSOFT-APNIC-AP |
| CIDR Block | 158.158.0.0/16 |
| RIR | ARIN |
| Country | SG |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 46% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 36% | 1 | 3 |
| geolocation | 27% | 2 | 2 |
| Overall | 28% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 20:33:43 UTC |
| Last Seen | 2026-08-12 18:54:03 UTC |
| Profile Built | 2026-08-12 19:04:50 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.