## IP Intelligence Briefing: 172.202.95.21/32
Classification: Cloud Infrastructure IP (Microsoft Azure)
Executive Summary
IP address 172.202.95.21 is classified as Microsoft Azure cloud infrastructure located in Des Moines, Iowa. The IP exhibits moderate risk characteristics (score: 50) with no active threat indicators. No open services were detected, and the IP is primarily characterized as firewalled with no services exposed.
Network Attribution
- ASN: 8075 (Microsoft Azure)
- Organization: Divya Quamara
- CIDR Block: 172.202.0.0/16
- Infrastructure Type: CloudCompute
- Network Role: Microsoft Azure provider with hosting capabilities
Geographic Location
- Country: United States (US)
- Region: Iowa (IA)
- City: Des Moines
- Coordinates: 41.6°N, -93.61°W
- Validation: Geo location plausible with multi-signal inference
Threat Assessment
- Risk Score: 50 (Moderate Risk)
- Abuse Confidence: Not applicable
- Threat Feeds: No active threat indicators
- Known Campaigns: None detected
- Blacklist Status: Listed on 2 of 8 DNSBL lists
- Tor/Proxy/VPN: Not detected
- Known Attacker: False
Network Behavior
- Open Ports: None detected
- Services: No services exposed (firewalled)
- DNS Resolution: No forward resolution confirmed
- PTR Records: None detected
- TLS Certificates: None detected
- HTTP Services: No HTTP title or banner detected
Historical Signals (20 observations)
Recent observations confirm:
- Consistent Microsoft Azure cloud classification
- Geographic stability in Des Moines, IA
- No persistent malicious activity observed
- Minimal operator score (0.1304)
- Some DNSBL listings with high severity noted in recent history
Neighborhood Analysis
- Subnet: 172.202.95.21/24
- Abuse Density: 0 (Clean)
- Neighbor Count: 0
- Threat Siblings: 0
Relationship Graph
Eight relationships identified, all classified as "Same Network" pointing to the "cloud" network designation. No external entity associations detected.
Recommended Actions
Based on the moderate risk profile and cloud infrastructure classification, the following actions are recommended:
1. Allow with Monitoring: Traffic to/from this IP may be permitted with logging enabled for baseline traffic analysis
2. DNSBL Review: Investigate the 2 DNSBL listings to determine specific reasons for inclusion
3. Traffic Pattern Analysis: Monitor for unusual outbound connections from Azure cloud infrastructure
4. No Immediate Block Required: No active threat indicators warrant immediate blocking
Conclusion
IP 172.202.95.21 represents legitimate Microsoft Azure cloud infrastructure. The moderate risk rating is primarily due to DNSBL listings rather than active malicious activity. No immediate defensive action is required beyond standard cloud traffic monitoring. The IP's clean neighborhood profile and lack of threat indicators support continued normal operation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 172.202.0.0/16 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 16:41:30 UTC |
| Last Seen | 2026-08-12 23:42:30 UTC |
| Profile Built | 2026-08-12 23:55:16 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.