INTELLIGENCE BRIEFING: 20.15.224.64
Classification: Microsoft Azure Cloud Infrastructure | Risk Level: Low (25/100) | Status: Under Observation
Infrastructure Profile
The target IP 20.15.224.64 belongs to Microsoft Corporation (AS8075) within the 20.0.0.0/11 CIDR block. The IP is classified as Microsoft Azure CloudCompute infrastructure, hosted in Des Moines, IA, US. The control plane indicates route instability (route stable: false) with 1 DNSBL listing across 8 total lists, though the primary blacklist count reports 0.
Network Services
No open ports detected. DNS reverse resolution returns azpdcg737vo2.stretchoid.com with forward resolution confirmed. TLS certificates and HTTP services are absent. The infrastructure operates in a firewalled state with no active services exposed.
Threat Indicators
- Risk Score: 25/100 (Low)
- Blacklist Status: 0 primary blacklist hits; 1 listing on 8 total DNSBL lists with "high" severity
- Threat Feeds: No active threat campaigns identified
- Abuse Confidence: Not assessed
Observation History (17 observations)
Recent signal activity (2026-07-29) indicates:
- Threat indicators present with 50 associated pulses
- High-severity blacklist listings (1 of 8 lists)
- DNSSEC validation confirmed (valid)
- No ownership changes recorded
- Threat persistence: 0 days; not classified as persistently malicious
Relationship Graph
- Same Network: MSFT (Microsoft Corporation)
- DNS Association: azpdcg737vo2.stretchoid.com
Neighborhood Analysis (20.15.224.0/24)
- Subnet abuse density: 0
- Active neighbors: 1 (20.15.224.135, risk score 25)
- Risk distribution: 1 low-risk IP detected
Recommendations for SOC
1. Monitor: Track DNSBL listing status; investigate the single high-severity listing
2. Allow: No immediate blocking required; Microsoft Azure infrastructure with no active services
3. Context: Legitimate cloud infrastructure; threat signals may be false positives or transient
4. Correlation: Review related IPs (20.15.224.135) for coordinated activity
5. Firewall: No specific rules required; standard Microsoft Azure traffic handling applies
Summary
This is a legitimate Microsoft Azure cloud IP with low-risk characteristics. While historical data shows transient threat associations and a high-severity DNSBL listing, the IP operates in a firewalled cloud environment with no active services. Monitor blacklist status but no immediate action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.0.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdcg737vo2.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdcg737vo2.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 01:41:17 UTC |
| Last Seen | 2026-08-12 17:23:10 UTC |
| Profile Built | 2026-08-12 17:37:34 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.