IPDebrief

172.210.249.152

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 172.210.249.152/32

Classification: Moderate Risk Cloud Infrastructure

Generated: 2026-06-21

Risk Score: 65/100

## Executive Summary

IP 172.210.249.152 is a Microsoft Azure cloud compute resource (ASN 8075) with a moderate risk profile. The IP is classified as cloud infrastructure with no open services detected. Despite the cloud environment classification, the IP shows elevated risk indicators including DNSBL listings and control plane anomalies requiring monitoring.

## Ownership and Network Classification

## Threat Indicators

Current threat assessment shows:

Anomalous Indicators:

## Historical Signal Analysis

Observation history reveals temporal signal patterns:

Persistence Metrics:

## Neighborhood Assessment

Subnet 172.210.249.0/24 analysis:

## Network Relationships

The IP has 12 relationship entries, all classified as "Same Network" targeting network value "cloud." No external entity relationships detected.

## Recommended Actions

Immediate Actions:

1. Monitoring: Increase logging verbosity and review recent activity from this IP

- Severity: High (Risk score 65/100)

- Rationale: Elevated risk score warrants enhanced visibility

Firewall Rules:

```

iptables: iptables -A INPUT -s 172.210.249.152 -j DROP

nftables: nft add rule inet filter input ip saddr 172.210.249.152 drop

nginx: deny 172.210.249.152;

pfsense: 172.210.249.152/32

Cloudflare WAF: Block IP (expression: ip.src eq 172.210.249.152)

AWS WAF: Block Addresses: 172.210.249.152/32

```

## Intelligence Assessment

This IP represents Microsoft Azure cloud infrastructure with moderate risk characteristics. The absence of open services and clean neighborhood profile suggests legitimate cloud usage, but the elevated risk score (65) combined with DNSBL listings warrants continued monitoring. The rapid first-hop RTT and timed-out hops indicate potential routing anomalies.

Priority: Monitor

Recommended Action: Implement firewall blocking with enhanced logging for forensic correlation if activity is observed.

---

*Data sourced from IPDebrief Intelligence Platform. All information is based on observed network signals and threat intelligence feeds.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVA
CityVirginia
TimezoneAmerica/New_York
Latitude36.67
Longitude-78.93

🏒 Ownership & Registration

OrganizationDivya Quamara
ASNAS8075
Network Namecloud
CIDR Block172.210.0.0/16
RIRARIN
CountryUS
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
24
routing
13%
11
services
19%
22
ownership
27%
23
reputation
22%
13
geolocation
27%
23
Overall22%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-30 10:58:22 UTC
Last Seen2026-06-29 07:34:09 UTC
Profile Built2026-06-29 07:39:20 UTC
Data FreshnessLive
Signal Types21
Total Observations21
πŸ” 21 signal types Β· 21 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.