# IP Intelligence Briefing: 172.173.200.62
Classification: Moderate Risk | Risk Score: 65/100 | Date: Current
## Executive Summary
The IP address 172.173.200.62 is a Microsoft Azure cloud compute instance hosted by Divya Quamara. While classified as cloud infrastructure, the address exhibits elevated risk characteristics with multiple DNSBL listings and active threat sibling connections within its /24 neighborhood.
## Technical Profile
Network Classification
- Infrastructure Type: CloudCompute (Microsoft Azure)
- ASN: 8075
- Geolocation: United States (Virginia, Washington region)
- Network Role: Single-Service Host / Cloud Hosting
- BGP Prefix: 172.160.0.0/11
Open Services
- Port 22/TCP: SSH (OpenSSH_8.9p1 Ubuntu-3ubuntu0.15)
Threat Indicators
- DNSBL Status: Listed on 3 of 8 threat feeds
- Blacklist Count: 0
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
## Risk Assessment
Control Plane Analysis
- Operator Score: 0.1304 (Minimal)
- Abuse Confidence: Not quantified
- ISP Abuse Contact: Available via RDAP
Neighborhood Context
- Subnet: 172.173.200.0/24
- Abuse Density: 1.0
- Subnet Classification: mostly_clean
- Threat Siblings: 1 active threat-adjacent neighbor
- Total Siblings: 1
## Observational History
Recent signal observations (16 total) indicate:
- Multiple geolocation signals confirming US presence with low confidence (0.28)
- DNSBL listing activity with maximum severity rating of "high"
- Consistent Microsoft Azure cloud infrastructure classification
- Minimal routing stability
## Threat Intelligence Narrative
The IP 172.173.200.62 operates within Microsoft Azure's cloud infrastructure in Virginia. While the subnet is classified as "mostly_clean" with minimal abuse density, the address itself is listed on three DNSBL feeds, suggesting prior reputation issues. The presence of one threat sibling within the /24 neighborhood indicates potential coordinated activity or shared infrastructure.
The open SSH port (22) on a cloud hosting instance warrants attention for potential unauthorized access or command-and-control activity. The moderate risk score (65) combined with multiple DNSBL listings and threat adjacency suggests this address may have been involved in prior malicious campaigns or is currently misused.
## Recommended Actions
Immediate
- Block inbound SSH traffic from this IP at perimeter firewalls
- Monitor for outbound connections to this IP from internal hosts
- Add to watchlist for correlation with threat intelligence feeds
Network Defense
- Implement rate limiting on port 22 if traffic from this IP is permitted
- Review firewall rules for Microsoft Azure ranges (172.160.0.0/11)
- Consider blocking at WAF if web traffic is observed
Intelligence Sharing
- Report to threat intelligence sharing platforms
- Correlate with other IPs in the 172.173.200.0/24 subnet
- Monitor for IP reputation changes over 24-48 hour period
## Conclusion
This IP represents a moderate risk cloud-hosted address with DNSBL listings and threat neighborhood proximity. While not definitively malicious, the combination of factors suggests defensive monitoring and blocking of inbound connections is warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-13 12:12:09 UTC |
| Last Seen | 2026-06-27 23:07:28 UTC |
| Profile Built | 2026-06-28 17:13:03 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 23 |
Full dossier details are available via our API.