IPDebrief

20.15.200.45

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP INTELLIGENCE BRIEFING: 20.15.200.45/32

---

SUBJECT: Microsoft Azure Cloud Infrastructure IP

DATE: Current Analysis Period

RISK LEVEL: MODERATE (Score: 50/100)

---

EXECUTIVE SUMMARY

IP 20.15.200.45 is identified as Microsoft Azure cloud infrastructure located in Des Moines, Iowa. The IP presents moderate risk characteristics with 2 DNS blacklist listings despite belonging to Microsoft's trusted cloud network. No active service ports are exposed, suggesting this IP may be used for infrastructure management or internal Azure services.

---

TECHNICAL PROFILE

AttributeValue
**Organization**Microsoft Corporation (ASN 8075)
**Network**20.0.0.0/11 (MSFT)
**Infrastructure**Microsoft Azure CloudCompute
**Geolocation**Des Moines, Iowa, US
**Risk Score**50 (Moderate)
**Blacklist Status**2 DNSBL listings
**Open Ports**None detected

---

KEY OBSERVATIONS

DNS Infrastructure: The IP resolves to `azpdcgc96rrb.stretchoid.com`, a Microsoft Azure DNS infrastructure hostname. Forward resolution confirmed with 1 PTR record.

Neighborhood Analysis: The /24 subnet (20.15.200.45/24) shows zero abuse density and is classified as clean. Only 1 sibling IP (20.15.200.1) exists in the range with a risk score of 25.

Historical Signals: 23 observations recorded showing consistent geolocation in Des Moines, IA. Previous neighborhood classification indicated "mostly_clean" status with 1 threat sibling detected in prior analysis period.

Control Plane: DNSSEC validated, CAA records present, route stability flagged as false. IP shows 2 DNSBL listings out of 8 total lists checked.

---

THREAT INDICATORS

IndicatorStatus
Known AttackerNo
Tor Exit NodeNo
Proxy/VPNNo
Active ScansNone detected
Open ServicesNone
Campaign CorrelationNone

---

RECOMMENDED ACTIONS

Firewall Rules: Block inbound traffic from this specific IP address:

Note: These rules are recommended based on risk score 50. Given this is Microsoft Azure infrastructure, false positives are possible. Correlate with internal traffic patterns before implementing permanent blocks.

---

ANALYST NOTES

This IP appears to be legitimate Azure cloud infrastructure with moderate risk scoring likely due to DNS blacklist associations rather than active malicious behavior. The subnet environment is clean with no neighboring threat activity. Monitor for any changes in geolocation consistency or service port openings.

Classification: Cloud Infrastructure / Azure DNS

Priority: LOW-MEDIUM

Action: Monitor or Block based on operational requirements

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionIA
CityDes Moines
TimezoneAmerica/Chicago
Latitude41.88
Longitude-93.10

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network NameMSFT
CIDR Block20.0.0.0/11
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRazpdcgc96rrb.stretchoid.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesazpdcgc96rrb.stretchoid.com

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
40%
24
routing
13%
11
services
19%
22
ownership
27%
23
reputation
32%
13
geolocation
27%
23
Overall26%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-29 04:30:20 UTC
Last Seen2026-08-12 23:09:30 UTC
Profile Built2026-08-12 23:11:47 UTC
Data FreshnessLive
Signal Types23
Total Observations24
πŸ” 23 signal types Β· 24 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.