INTELLIGENCE BRIEFING: 172.213.17.107/32
Assessment: MODERATE RISK - Cloud Infrastructure with Blacklist Reputation Issues
Classification: Microsoft Azure CloudCompute
Location: Milan, Lombardy, Italy (Geo: IT | Confidence: 0.28)
ASN: 8075 (Microsoft Corporation)
Network Block: 172.208.0.0/13
---
KEY FINDINGS
Reputation Status:
- Overall Risk Score: 65/100 (Moderate)
- DNSBL Listed: 3 of 8 threat intelligence lists
- Blacklist Severity: High on active listings
- Abuse Confidence: Not explicitly scored
Infrastructure Profile:
- Infrastructure Type: CloudCompute (Microsoft Azure)
- Service Status: Firewalled / No Services
- Open Ports: None detected
- Hosted Domains: None
- DNSSEC: Valid
Threat Indicators:
- No active threat campaigns detected
- No known attacker signatures
- No spam source indicators
- No Tor exit node activity
- No proxy/VPN indicators
- No hosting abuse indicators
- Threat Observation Count: 0 (not persistently malicious)
Geolocation Validation:
- Country: Italy (IT)
- Region: Lombardy
- City: Milan
- Accuracy Radius: 750km
- Geo Consensus: True
---
NEIGHBORHOOD ANALYSIS
- Subnet: 172.213.17.0/24
- Neighbor Count: 2 IPs
- Abuse Density: 0 (clean neighborhood)
- Neighbor Risk Scores: 25/100 (Low)
- 172.213.17.76: Risk 25, Authority 50
- 172.213.17.92: Risk 25, Authority 50
---
OBSERVATION HISTORY
- Total Observations: 12
- Latest Activity: 2026-07-30
- Recent Signals:
- Blacklist listings (3/8 lists, max severity: high)
- DNSSEC validation confirmed
- ASN attribution: Microsoft Corporation
- Geolocation inference: Italy (low confidence)
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: False
---
RECOMMENDED ACTIONS
Firewall/IPS Rules:
```
# Block on port 443 only (if traffic observed)
iptables -A INPUT -p tcp -d 172.213.17.107/32 --dport 443 -j DROP
# Or allow with rate limiting
iptables -A INPUT -p tcp -d 172.213.17.107/32 --dport 443 -m limit --limit 5/min -j ACCEPT
```
Cloudflare WAF:
```yaml
# Create rule for 172.213.17.107/32
- type: ip
- action: challenge
- source: 172.213.17.107/32
- severity: medium
```
AWS WAF:
```
# Block IP with rate-based rule
IPSetId: aws:ips/172.213.17.107/32
Priority: 100
Action: block
```
SOC Monitoring:
- Monitor for outbound connections from internal hosts to this IP
- Alert if DNS queries observed for this IP
- Track blacklist reputation changes weekly
- No immediate block recommended; monitor for traffic anomalies
---
INTELLIGENCE SUMMARY
IP 172.213.17.107 is a Microsoft Azure cloud infrastructure endpoint located in Milan, Italy. The moderate risk score (65) is primarily driven by blacklist reputation (3 of 8 threat feeds) rather than active malicious behavior. No open services or ports detected; the IP appears firewalled. Neighborhood analysis shows clean adjacent IPs with low risk scores. No persistent malicious activity observed. Recommended monitoring approach: allow with rate limiting or challenge-based WAF protection rather than outright blocking.
Confidence Level: High (Infrastructure type verified, blacklist activity confirmed)
Last Updated: 2026-07-30
Intel Source: IPDebrief Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 172.213.0.0/16 |
| RIR | ARIN |
| Country | IT |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 36% | 3 | 4 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 2 |
| Overall | 27% | 12 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 21:00:27 UTC |
| Last Seen | 2026-08-12 19:53:43 UTC |
| Profile Built | 2026-08-12 20:07:39 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.