# IP INTELLIGENCE BRIEFING: 172.174.5.146/32
Date: 2026-06-18
Classification: Moderate Risk
Risk Score: 65/100
---
## EXECUTIVE SUMMARY
IP address 172.174.5.146 is associated with Microsoft Azure infrastructure (ASN 8075) and has been flagged as a moderate-risk endpoint. The IP shows evidence of blacklist presence with 3 active listings out of 8 total, maximum severity rated "high" as of June 18, 2026. While geolocation data indicates US (Washington, VA), there are validation inconsistencies and cross-continental reputation signals. No active services, open ports, or certificate infrastructure detected.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **IP Address** | 172.174.5.146/32 |
| **ASN** | 8075 |
| **Organization** | Divya Quamara |
| **RIR** | ARIN |
| **Cloud Provider** | Microsoft Azure |
| **Infrastructure Type** | Cloud |
| **Country** | US (Virginia) |
| **Geo Validation** | ICMP blocked - unable to validate |
| **Route Stability** | Unstable |
---
## THREAT INDICATORS
Blacklist Status: 3 active listings, 8 total (max severity: high)
DNSBL Lists: 3/8
Threat Feeds: None correlated
Campaign Matches: 0
Known Attacker: No
Tor Exit Node: No
Spam Source: No
Key Observations:
- Listed on multiple threat feeds as of 2026-06-18
- AlienVault OTX correlation detected (2026-06-13)
- Geolocation inconsistencies (claimed DE coordinates vs US registration)
---
## NETWORK BEHAVIOR & SERVICES
Open Ports: None detected
TLS Certificates: None
HTTP Services: None
DNS Resolution: Forward resolution count: 0
PTR Hostnames: None
Network Role: Firewalled / No Services
Abuse Confidence: Insufficient data for scoring
Operator Score: 0.2174 (Minimal)
---
## NEIGHBORHOOD ANALYSIS
Subnet: 172.174.5.146/24
Abuse Density: 0
Classification: Mostly Clean
Threat Siblings: 1
Active Siblings: 0
---
## OBSERVATION HISTORY
Total observations: 23
Recent Activity:
- 2026-06-18: Listed on multiple blacklists (3 active, max severity high)
- 2026-06-17: ICMP probe validation failed (blocked)
- 2026-06-13: AlienVault OTX correlation from Germany (DE)
Persistence: Threat observation count: 1
Is Persistently Malicious: No
---
## RELATIONSHIP GRAPH
Total relationships: 46
Primary Connections: Same Network (cloud infrastructure)
Correlated Entities: 41 additional cloud network associations
---
## RECOMMENDED ACTIONS
Priority: High
Category: Monitoring
| Platform | Recommended Action |
|---|---|
| **Monitoring** | Increase logging verbosity and review recent activity from this IP |
Firewall Rules:
- iptables: `iptables -A INPUT -s 172.174.5.146 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 172.174.5.146 drop`
- nginx: `deny 172.174.5.146;`
- pfSense: `172.174.5.146/32`
- Cloudflare WAF: Block IP (expression: `ip.src eq 172.174.5.146`)
- AWS WAF: Add 172.174.5.146/32 to blocked addresses
Recommendation: Implement blocking rules and enable enhanced logging to correlate with any inbound connection attempts. Review historical traffic patterns for potential lateral movement indicators.
---
Analyst Notes: Risk score elevated due to blacklist presence. While no active services detected, the IP should be monitored for potential exploitation attempts. Consider contextual blocking based on organizational threat posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 21% | 9 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:54 UTC |
| Last Seen | 2026-06-27 01:52:41 UTC |
| Profile Built | 2026-06-27 20:00:22 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.