# IP Intelligence Briefing: 172.200.228.35/32
## Executive Summary
The target IP address 172.200.228.35/32 presents a high-risk profile (Risk Score: 80/100) associated with Microsoft Azure cloud infrastructure. The IP maintains elevated threat indicators including DNSBL listings and was flagged as requiring critical monitoring attention.
## Network Classification
The address belongs to ASN 8075 (Microsoft Azure), classified as cloud compute infrastructure. Geolocation data places the IP in Boydton, Virginia, US, with geo-validation showing plausible origin (distance: 6,553.3 km). The BGP prefix 172.200.0.0/13 remains the origin for this network.
## Risk Profile
The IP received a risk score of 80/100, labeled "High Risk." Risk breakdown data was not populated in the full profile. Control plane analysis indicated 4 DNSBL listings across 8 total blacklists with operator score of 0.1304. The IP is not classified as a Tor exit node, known attacker, or spam source, though blacklist listings suggest prior abuse activity.
## Threat Indicators
No specific threat indicators were detected in the threat feeds section. The IP is not flagged as a known attacker or Tor exit node. However, the abuse confidence score was not populated, and threat observation count registered at 1.
## Historical Observations
Analysis of 19 observations revealed temporal signal variations. Recent observations (June 2026) included:
- Operator score assessments showing "Minimal" classification
- Reputation signals across 6 dimensions with data sufficiency of 1
- DNSBL listings with high severity ratings (4 total listings, max severity: high)
The IP did not demonstrate persistent malicious behavior (threatPersistenceDays: 0).
## Infrastructure Analysis
The IP resides within Microsoft Azure cloud infrastructure with no active services detected. DNS analysis showed no forward resolution, no PTR hostnames, and no hosted domains. No email authentication records (SPF/DMARC) were present. Open port scanning revealed no active services on standard ports.
## Neighborhood Assessment
The /24 subnet (172.200.228.0/24) showed abuse density of 1 with classification "mostly_clean." Analysis identified 1 total sibling IP with 1 threat sibling. The subnet inherited risk score of 2.
## Network Relationships
Twenty-one relationships were identified, all categorized as "Same Network" with target type "cloud," indicating the IP operates within Microsoft Azure cloud infrastructure.
## Recommended Actions
Security operations teams were advised to increase logging verbosity and review recent activity from this IP due to the elevated risk score. Recommended firewall rules were generated for iptables, nftables, nginx, pfSense, Cloudflare WAF, and AWS WAF to block traffic from 172.200.228.35/32.
Classification: High Risk
Last Updated: 2026-06-22
Recommended Action: Implement blocking rules and enhance monitoring
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 18% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:54 UTC |
| Last Seen | 2026-06-27 01:54:52 UTC |
| Profile Built | 2026-06-27 20:01:35 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 25 |
Full dossier details are available via our API.