## INTELLIGENCE BRIEFING: 20.168.15.107/32
Classification: Legitimate Cloud Infrastructure | Risk Level: Moderate | Primary Provider: Microsoft Azure
---
EXECUTIVE SUMMARY
IP 20.168.15.107 is a Microsoft Azure cloud infrastructure address within the 20.160.0.0/12 CIDR block (MSFT/8075). The IP demonstrates a moderate risk profile (40/100) consistent with legitimate cloud hosting. No active threat campaigns or known attacker indicators detected. The IP resolves to a Microsoft Azure datacenter hostname (azpdwsw1de7x.stretchoid.com) with no open services exposed.
---
INFRASTRUCTURE PROFILE
Ownership: Microsoft Corporation | ASN: 8075 | Organization: MSFT
Geolocation: Phoenix, AZ, US | Coordinates: 33.45°N, 112.07°W
Network Classification:
- Infrastructure Type: CloudCompute
- Provider: Microsoft Azure
- Status: Firewalled / No Services
- IP Classification: Cloud Infrastructure (Not Bogon)
DNS Resolution:
- PTR Hostname: azpdwsw1de7x.stretchoid.com
- Forward Resolution: Confirmed
- Hosted Domains: None
- SPF/DMARC: Not configured
---
THREAT INDICATORS
Current Threat Status: CLEAN
- Abuse Confidence: Not elevated
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 1 (of 8 DNSBLs)
- Active Threat Feeds: None
Control Plane Data:
- RPKI State: Valid
- DNSSEC: Valid
- Route Stability: Stable
- Operator Score: 0.1304 (Minimal)
---
OBSERVATION HISTORY
Total Signals Observed: 24
Recent Activity (2026-08-05):
- Multiple DNS and ownership signals recorded
- High-severity DNSBL listings detected (2 of 8 total lists)
- Subnet classification: Clean with 0 abuse density
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence: 0 days
- Persistently Malicious: No
- Campaign Correlation: None
---
NEIGHBORHOOD ANALYSIS
Subnet: 20.168.15.0/24
- Abuse Density: 0.0 (Clean)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- Risk Distribution: No high/medium threat neighbors identified
---
RELATIONSHIP MAPPING
Primary Associations:
- MSFT Network (20.168.15.107/24)
- DNS Hostname: azpdwsw1de7x.stretchoid.com
Relationship Count: 11 total (8 DNS associations, 3 network associations)
---
RECOMMENDED ACTIONS
Risk Score: 40/100
Recommended Actions:
- No immediate blocking recommended
- IP represents legitimate Azure infrastructure
- Monitor for behavioral changes if associated with suspicious traffic
Firewall Rules (if blocking required):
- iptables: `-A INPUT -s 20.168.15.107 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 20.168.15.107 drop`
- Cloudflare WAF: Block with expression `ip.src eq 20.168.15.107`
- AWS WAF: Add `20.168.15.107/32` to IP set
---
ASSESSMENT
This IP address represents legitimate Microsoft Azure cloud infrastructure. The moderate risk score (40) is typical for cloud provider addresses with DNSBL listings. No evidence of malicious activity or threat campaigns. The "stretchoid.com" hostname indicates this is a Microsoft Azure service endpoint. Standard operational traffic is expected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.160.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdwsw1de7x.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdwsw1de7x.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-21 12:55:14 UTC |
| Last Seen | 2026-08-12 15:52:49 UTC |
| Profile Built | 2026-08-12 16:06:29 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.