IP Intelligence Briefing: 172.171.3.138
Date: 2026-06-01
---
**1. Core Profile**
- Risk Score: Moderate (50/100)
- Ownership: Registered to Divya Quamara (Microsoft Azure infrastructure).
- Geolocation: Des Moines, IA, US (inferred via DNSSEC validation).
- Network Role: Cloud compute instance (Microsoft Azure).
- Threat Indicators: No malicious activity detected (no blacklists, spam, or known attacker associations).
---
**2. Observation History (30-Day Trend)**
- Risk Signals: Minimal fluctuations; consistently low threat scores.
- DNSSEC Validity: Confirmed valid for subdomain `138.3.171.172.in-addr.arpa`.
- Abuse Confidence: 0.13 (low risk of misuse).
- Route Stability: BGP route changes: 0 in 30 days; stable prefix (`172.160.0.0/11`).
---
**3. Network Relationships**
- Linked Entities:
- Same network: "cloud" (Microsoft Azure infrastructure).
- Subnet: 172.171.3.0/24.
- Neighbors:
- 172.171.3.77: No risk score recorded; subnet abuse density: 0%.
---
**4. Threat Context**
- No Active Threats: No malware indicators, open ports, or DNS anomalies.
- Cloud Hosting: Likely a legitimate Azure VM with restricted access (firewalled, no public services).
- DNS Behavior: No email auth (SPF/DKIM) or domain hosting detected.
---
**5. Recommendations**
1. Verify Asset Validity: Confirm if this IP is a known, authorized cloud asset.
2. Monitor Subnet: Track neighboring IPs (e.g., 172.171.3.77) for potential lateral movement.
3. Maintain Baseline: Continue monitoring for unexpected DNS changes or route instability.
4. Access Controls: Ensure strict firewall rules limit access to this Azure instance.
Conclusion: This IP appears to be a low-risk, legitimate Azure cloud instance with no current malicious activity. No immediate action required, but ongoing monitoring is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 172.171.0.0/16 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ruohrkvtawbavfs.centralus.cloudapp.azure.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ruohrkvtawbavfs.centralus.cloudapp.azure.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 17:02:31 UTC |
| Last Seen | 2026-06-29 07:53:55 UTC |
| Profile Built | 2026-06-29 08:03:48 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.