# INTELLIGENCE BRIEFING: 20.168.7.149/32
Date: 2026-07-30
Classification: Low Risk
Risk Score: 25/100
---
## EXECUTIVE SUMMARY
IP address 20.168.7.149 is a Microsoft Azure cloud infrastructure endpoint with low risk characteristics. No active threat indicators detected. The IP operates as a firewalled cloud resource with no open services.
---
## OWNERSHIP & INFRASTRUCTURE
- Organization: Microsoft Corporation (MSFT)
- ASN: 8075
- CIDR Block: 20.160.0.0/12
- Geolocation: Phoenix, Arizona, US (33.45°N, 112.07°W)
- Network Role: Microsoft Azure Cloud Provider
- Infrastructure Type: Cloud Infrastructure
---
## THREAT ASSESSMENT
| Indicator | Status |
|---|---|
| Threat Indicators | None Detected |
| Known Attacker | False |
| Tor Exit Node | False |
| Spam Source | False |
| Blacklist Count | 0 |
| Known Campaigns | None |
Risk Breakdown:
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
---
## NETWORK CLASSIFICATION
- Classification: Cloud Infrastructure
- Cloud Provider: Microsoft Azure
- Service Purpose: Firewalled / No Services
- DNSSEC: Valid
- CAA Records: Present
- Operator Score: 0.3478 (Basic)
---
## DNS & RESOLUTION
- PTR Record: azpdwg4vt4s9.stretchoid.com
- Forward Resolution: Confirmed (1 record)
- Email Authentication: SPF/DMARC Not Configured
- Domain: stretchoid.com
---
## SERVICE POSTURE
- Open Ports: None Detected
- HTTP/HTTPS: No Services
- TLS Certificate: None
- Server Banner: None
- Status: No Active Services (Firewalled)
---
## NEIGHBORHOOD ANALYSIS
Subnet: 20.168.7.0/24
- Abuse Density: 1 (Low)
- Classification: Mostly Clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
---
## RELATIONSHIP GRAPH
Identified Associations:
- Same Network: MSFT (Microsoft)
- DNS Association: azpdwg4vt4s9.stretchoid.com (Multiple entries)
---
## OBSERVATION HISTORY
Signal Count: 20 Observations
Most Recent: 2026-07-30T16:45:30Z
Threat Persistence: 0 Days
Persistently Malicious: False
Recent Signal Types Observed:
- Ownership stability
- Subnet abuse density
- Geolocation inference (Phoenix, AZ)
- Service scan results
- Control plane assessment
---
## RECOMMENDED ACTIONS
Firewall Rules: Not Recommended
Monitoring Priority: Standard
Investigation Required: No
Rationale: This IP is Microsoft Azure cloud infrastructure with no open services and no threat indicators. The low risk score (25) and clean neighborhood profile indicate benign cloud resource behavior.
---
## ANALYST NOTES
This IP represents legitimate Microsoft Azure cloud infrastructure. The absence of open ports and services is consistent with cloud infrastructure that may be backend-facing or heavily restricted. The DNS resolution to stretchoid.com aligns with Microsoft's cloud service patterns. No defensive action required beyond standard monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.160.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdwg4vt4s9.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdwg4vt4s9.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 10:06:36 UTC |
| Last Seen | 2026-08-12 22:25:32 UTC |
| Profile Built | 2026-08-12 22:30:28 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.