IP Intelligence Briefing for 172.202.117.125
Date: 2026-06-12
---
**1. Core Profile**
- Risk Score: Moderate (50/100)
- Provider: Microsoft Azure (CloudCompute)
- Ownership: Divya Quamara (AS8075)
- Geolocation: Des Moines, IA, US (ARIN registered)
- Network Role: Firewalled cloud infrastructure (no open services detected)
- Threat Indicators: No malicious activity observed; no blacklisted IPs or campaigns linked.
---
**2. Threat & Behavior**
- DNS Associations: Resolves to `azpdcswth3u0.stretchoid.com` (no malicious domains detected).
- Historical Signals:
- Low-confidence DNS observations (2026-06-01 to 2026-06-12).
- No persistent malicious activity or honeypot hits.
- Abuse Confidence: Null (no confirmed abuse).
---
**3. Network Relationships**
- Same Network: Linked to Azure cloud infrastructure (172.202.0.0/16).
- DNS Hostnames: `azpdcswth3u0.stretchoid.com` (no known malicious domains).
- Subnet Neighbors:
- 172.202.117.124: Low risk (0/100).
- 172.202.117.177: Moderate risk (25/100).
- 172.202.117.213: Unknown risk.
- 172.202.117.223: Moderate risk (40/100).
---
**4. Recommendations**
- Monitor Neighbors: Focus on 172.202.117.177 and 172.202.117.223 for potential risk escalation.
- Verify DNS: Confirm `stretchoid.com` is legitimate; no signs of spoofing or phishing.
- Network Segmentation: Ensure Azure cloud resources are isolated from internal networks.
- Threat Feeds: Cross-check with DNSBLs for any emerging threats in the 172.202.0.0/16 subnet.
---
Conclusion: This IP is a legitimate Microsoft Azure cloud instance with no immediate threats. However, its moderate risk score and neighboring IPs warrant continued monitoring for anomalies. No immediate mitigation required, but proactive network hygiene is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 172.202.0.0/16 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdcswth3u0.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdcswth3u0.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-01 17:53:26 UTC |
| Last Seen | 2026-06-21 07:43:48 UTC |
| Profile Built | 2026-06-21 07:50:20 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.