# INTELLIGENCE BRIEFING: 20.118.233.215/32
Classification: Low Risk
Date of Analysis: 2026-06-15
Target: Microsoft Azure Infrastructure IP
---
## Executive Summary
IP address 20.118.233.215 is assigned to Microsoft Corporation (ASN 8075) within Microsoft Azure cloud infrastructure. The address registers a low-risk profile (score: 25/100) with no active open services detected. However, historical signal observations indicate intermittent threat associations with a Basic operator classification.
---
## Ownership and Geolocation
- Organization: Microsoft Corporation
- ASN: AS8075
- Infrastructure: Microsoft Azure (CloudCompute)
- Location: Des Moines, IA, US (America/Chicago timezone)
- CIDR Block: 20.118.233.0/24 subnet
---
## Network Characteristics
- Network Role: Microsoft Azure cloud environment
- Infrastructure Type: CloudCompute
- Connection Type: Firewalled / No Services exposed
- Open Ports: None detected
- DNS PTR Record: azpdcgj4auuy.stretchoid.com
- Reverse DNS: stretchoid.com (forward-resolved)
- TLS/HTTP Services: No active services
---
## Threat Assessment
Current Risk Score: 25 (Low Risk)
Historical Signals (21 observations):
- Recent observation (2026-06-15) flagged threat indicators with reputation score of 0
- Operator score: 0.3478 (Basic classification)
- Multiple threat pulses detected in latest signal
- DNSBL listings: 1 of 8 total lists
- No known campaigns or correlated IP activity
Abuse Indicators:
- Abuse confidence score: Not available
- Blacklist count: 0
- Is known attacker: False
- Is spam source: False
- Is Tor exit: False
---
## Neighborhood Analysis
Subnet: 20.118.233.0/24
- Abuse Density: 1 (mostly_clean classification)
- Threat Siblings: 1 detected in subnet
- Active Siblings: 1
- Total Siblings: 1
---
## Relationships
- DNS Associations: Multiple associations to stretchoid.com domain
- Network Affiliation: MSFT network relationships
- Total Relationships: 30 (primarily DNS and network-based)
---
## Recommended Actions
Based on current risk profile:
1. Monitor: Continue passive monitoring for changes in threat indicators
2. Allow: No immediate blocking required for Azure infrastructure IP
3. Context: Verify any suspicious traffic patterns against baseline Azure behavior
4. Documentation: Record for future reference if associated with security incidents
---
## Intelligence Notes
This IP address represents Microsoft Azure cloud infrastructure with intermittent threat signal activity in historical observations. The low current risk score (25/100) and absence of open services suggest legitimate cloud workload activity. Security teams should correlate any suspicious activity with this IP against other intelligence sources before taking remediation actions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdcgj4auuy.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdcgj4auuy.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-18 15:26:17 UTC |
| Last Seen | 2026-06-28 07:31:03 UTC |
| Profile Built | 2026-06-29 01:35:48 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.