# IP Intelligence Briefing: 172.174.236.9/32
## Executive Summary
IP address 172.174.236.9 presents a moderate risk profile (Risk Score: 40/100) associated with cloud infrastructure in Virginia, US. The IP is hosted on Microsoft Azure but exhibits DNS associations with suspicious hostname patterns and conflicting geolocation data. No active threat indicators detected.
## Profile Assessment
Ownership & Classification
- ASN: 8075
- Organization: Divya Quamara / cloud
- CIDR Block: 172.174.0.0/16
- Infrastructure Type: CloudCompute (Microsoft Azure)
- Status: Firewalled / No Services
Geolocation
- Primary: Virginia, US (37.37°N, -79.46°W)
- Alternate Signal: Germany (51.2993°N, 9.491°E) with 0.95 confidence
- Note: Geolocation consensus false; data inconsistent across sources
DNS Analysis
- PTR Record: azpdesgtfgud.stretchoid.com
- Forward Resolution: Confirmed
- Domain: stretchoid.com
- Assessment: Random alphanumeric hostname pattern detected; stretchoid.com domain requires monitoring
## Threat Indicators
Current Status
- Reputation: Moderate Risk
- Blacklist Count: 0
- DNSBL Listings: 2 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaigns: None
Control Plane
- Operator Score: 0.3478 (Basic)
- Route Stability: False
- DNSSEC: Valid
- RPKI State: Unavailable
## Historical Observations
Analysis of 20 historical signals indicates:
- One observation (2026-07-29T18:31:05) associated with Germany with threat indicators and 50 pulse feed correlations
- Multiple observations confirming clean subnet classification (abuse density: 0)
- No persistent malicious activity detected
- Ownership changes: 0
## Network Relationships
DNS Associations
- azpdesgtfgud.stretchoid.com (multiple records)
- Network associations: "cloud" infrastructure
Neighborhood Analysis
- Subnet: 172.174.236.9/24
- Abuse Density: 0
- Threat Siblings: 0
- Active Siblings: 0
- Classification: Clean
## Recommended Actions
1. Monitor DNS Activity: The hostname pattern (azpdesgtfgud.stretchoid.com) suggests potential temporary or compromised infrastructure. Monitor for additional DNS queries.
2. Investigate Geolocation Discrepancy: Conflicting US and Germany geolocation data warrants investigation. Verify legitimate business use in both regions.
3. Monitor for Service Activation: Current state shows no open ports. Alert on any service openings or port scans.
4. Review DNSBL Listings: Two DNSBL listings detected despite zero blacklist count. Investigate sources and determine if listings are accurate or stale.
5. Add to Watchlist: Moderate risk score with suspicious hostname patterns. Recommend addition to monitoring queue for 30-day observation period.
## Intelligence Conclusion
IP 172.174.236.9 is a Microsoft Azure cloud endpoint with moderate risk characteristics. The primary concern is DNS association with a random hostname pattern (azpdesgtfgud.stretchoid.com) combined with geolocation inconsistencies. No active exploitation or attack activity detected. Recommend monitoring for service activation and continued DNS activity. No immediate blocking recommended; observe for threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 172.174.0.0/16 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdesgtfgud.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdesgtfgud.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 13:56:26 UTC |
| Last Seen | 2026-08-12 17:41:36 UTC |
| Profile Built | 2026-08-12 17:49:01 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.