IP INTELLIGENCE BRIEFING: 20.15.200.45/32
---
SUBJECT: Microsoft Azure Cloud Infrastructure IP
DATE: Current Analysis Period
RISK LEVEL: MODERATE (Score: 50/100)
---
EXECUTIVE SUMMARY
IP 20.15.200.45 is identified as Microsoft Azure cloud infrastructure located in Des Moines, Iowa. The IP presents moderate risk characteristics with 2 DNS blacklist listings despite belonging to Microsoft's trusted cloud network. No active service ports are exposed, suggesting this IP may be used for infrastructure management or internal Azure services.
---
TECHNICAL PROFILE
| Attribute | Value |
|---|---|
| **Organization** | Microsoft Corporation (ASN 8075) |
| **Network** | 20.0.0.0/11 (MSFT) |
| **Infrastructure** | Microsoft Azure CloudCompute |
| **Geolocation** | Des Moines, Iowa, US |
| **Risk Score** | 50 (Moderate) |
| **Blacklist Status** | 2 DNSBL listings |
| **Open Ports** | None detected |
---
KEY OBSERVATIONS
DNS Infrastructure: The IP resolves to `azpdcgc96rrb.stretchoid.com`, a Microsoft Azure DNS infrastructure hostname. Forward resolution confirmed with 1 PTR record.
Neighborhood Analysis: The /24 subnet (20.15.200.45/24) shows zero abuse density and is classified as clean. Only 1 sibling IP (20.15.200.1) exists in the range with a risk score of 25.
Historical Signals: 23 observations recorded showing consistent geolocation in Des Moines, IA. Previous neighborhood classification indicated "mostly_clean" status with 1 threat sibling detected in prior analysis period.
Control Plane: DNSSEC validated, CAA records present, route stability flagged as false. IP shows 2 DNSBL listings out of 8 total lists checked.
---
THREAT INDICATORS
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Tor Exit Node | No |
| Proxy/VPN | No |
| Active Scans | None detected |
| Open Services | None |
| Campaign Correlation | None |
---
RECOMMENDED ACTIONS
Firewall Rules: Block inbound traffic from this specific IP address:
- `iptables -A INPUT -s 20.15.200.45 -j DROP`
- `nft add rule inet filter input ip saddr 20.15.200.45 drop`
Note: These rules are recommended based on risk score 50. Given this is Microsoft Azure infrastructure, false positives are possible. Correlate with internal traffic patterns before implementing permanent blocks.
---
ANALYST NOTES
This IP appears to be legitimate Azure cloud infrastructure with moderate risk scoring likely due to DNS blacklist associations rather than active malicious behavior. The subnet environment is clean with no neighboring threat activity. Monitor for any changes in geolocation consistency or service port openings.
Classification: Cloud Infrastructure / Azure DNS
Priority: LOW-MEDIUM
Action: Monitor or Block based on operational requirements
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.0.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdcgc96rrb.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdcgc96rrb.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 04:30:20 UTC |
| Last Seen | 2026-08-12 23:09:30 UTC |
| Profile Built | 2026-08-12 23:11:47 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.