# IP Intelligence Briefing: 172.196.32.64/32
## Executive Summary
IP 172.196.32.64 is classified as Moderate Risk (Risk Score: 40). The address is hosted on Microsoft Azure cloud infrastructure under ASN 8075. While no active threat indicators are present, conflicting geolocation signals and DNSBL listings warrant monitoring.
---
## Current Risk Profile
| Metric | Value |
|---|---|
| Risk Score | 40 (Moderate) |
| Reputation | Moderate Risk |
| ASN | 8075 |
| Organization | Divya Quamara |
| Network Name | cloud |
| Infrastructure | Microsoft Azure (CloudCompute) |
| Country | NZ (inconsistent signals) |
| City | Auckland |
---
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Threat Feeds: None detected
- Abuse Confidence Score: Not available
---
## Network Classification
- Infrastructure Type: CloudCompute
- Provider: Microsoft Azure
- Hosting: Yes
- Open Ports: None detected
- TLS Certificate: None
- Active Services: No open services identified
---
## Control Plane Analysis
- Origin ASN: 8075
- BGP Prefix: 172.192.0.0/13
- Route Stability: Unstable (isRouteStable: false)
- DNSBL Status: Listed on 2 of 8 checks
- RPKI State: Not verified
- IRR Consistency: Not verified
---
## Geolocation Intelligence
Significant signal inconsistency observed:
- Primary Location: Auckland, NZ
- Conflicting Signal: Australia (AU) detected via AlienVault OTX
- GeoPlausible Flag: False (indicates location validation failure)
- Consensus: False (multiple conflicting sources)
---
## Observation History (15 Signals)
Recent observations reveal notable signal conflicts:
1. Ownership Attribution: Confirmed to "Divya Quamara" via ARIN
2. Geolocation Conflict: One signal identified as "foxtel management pty ltd" (AU) with threat indicators; another shows Microsoft Azure infrastructure
3. Threat Persistence: 0 days observed
4. Malicious Activity: Not persistently malicious
---
## Subnet Analysis (172.196.32.0/24)
- Neighbor Count: 0 siblings detected
- Abuse Density: 0
- Risk Distribution: None (high/medium/low = 0)
- Classification: No inherited risk from subnet
---
## Related Entities
- Network Relationships: 2 entries (both "Same Network" type pointing to "cloud")
- No Associated Hostnames: None identified
- No Certificate Associations: None detected
---
## Recommended Actions
Firewall Rules (iptables/nftables)
```bash
# Block outbound traffic from this IP (if observed externally)
iptables -A OUTPUT -d 172.196.32.64 -j DROP
iptables -A OUTPUT -p tcp --dport 80 -d 172.196.32.64 -j DROP
iptables -A OUTPUT -p tcp --dport 443 -d 172.196.32.64 -j DROP
```
WAF Rules (Cloudflare/AWS)
```yaml
# Block IP at WAF level
ip: 172.196.32.64
action: block
reason: moderate-risk-cloud-traffic
```
Monitoring Priority
- Medium Priority: Monitor for increased activity from this IP
- Watch List: DNSBL listings may increase
- Geolocation Validation: Continue monitoring for location signal consistency
---
## Analyst Notes
This IP presents a moderate risk profile primarily due to conflicting geolocation signals and DNSBL listings. The Microsoft Azure cloud hosting context suggests legitimate cloud infrastructure, but the location inconsistencies (NZ vs AU) and the "foxtel management pty ltd" association require continued observation. No active exploitation indicators or malicious behavior have been detected. Recommend standard monitoring protocols with escalation if threat indicators emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 172.196.0.0/16 |
| RIR | ARIN |
| Country | NZ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 13:56:26 UTC |
| Last Seen | 2026-08-12 17:41:56 UTC |
| Profile Built | 2026-08-12 17:49:01 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.