IPDebrief

20.169.107.167

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

IP Address: 20.169.107.167/32

Classification: Cloud Infrastructure / Microsoft Azure

Risk Assessment: LOW RISK (Score: 25/100)

Report Date: Current Analysis Cycle

---

## EXECUTIVE SUMMARY

20.169.107.167 is identified as Microsoft Azure cloud infrastructure operating within the Phoenix, AZ data center region (ASN 8075). The IP demonstrates low-risk characteristics consistent with legitimate cloud hosting services. No active malicious indicators, known campaigns, or threat feed associations detected. The address resolves to stretchoid.com domain infrastructure and is classified as Microsoft Azure cloud compute environment.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
OrganizationMicrosoft Corporation
ASN8075
RIRARIN
Network Block20.160.0.0/12 (BGP prefix)
Infrastructure TypeCloudCompute
Cloud ProviderMicrosoft Azure
Hosting ClassificationYes

DNS Resolution: The IP resolves to `azpdwg445sor.stretchoid.com` (forward confirmed). PTR record matches forward resolution.

---

## GEOLOCATION DATA

FieldValue
CountryUnited States (US)
RegionArizona (AZ)
CityPhoenix
Coordinates33.45°N, -112.07°W
TimezoneAmerica/Phoenix
Accuracy Radius150 km
GeoConsensusTrue

---

## THREAT INDICATORS

IndicatorStatus
Risk Score25 (Low)
Abuse Confidence ScoreNot Available
Blacklist Count0
Known AttackerNo
Spam SourceNo
Tor Exit NodeNo
Threat Persistence0 days
Campaign LikelihoodNone

Threat Feeds: No associations with known threat feeds or campaigns detected.

---

## NETWORK CLASSIFICATION FLAGS

FlagStatus
Is CloudYes
Is CDNNo
Is VPNNo
Is ProxyNo
Is TorNo
Is HostingYes
Is ResidentialNo
Is MobileNo
Is BogonNo
Is AnycastNo

Service State: No open ports detected (firewalled/no services exposed).

---

## TEMPORAL ANALYSIS

Observation History: 23 total observations recorded across analysis period.

Consistency Pattern: Infrastructure classification remained stable throughout observation window. Recent observations (2026-06-28 through 2026-06-20) consistently confirm Microsoft Azure cloud infrastructure status with no ownership changes or malicious behavior indicators.

Threat Persistence: None observed. No persistent malicious activity detected.

---

## NEIGHBORHOOD ANALYSIS (20.169.107.0/24)

MetricValue
Subnet Abuse Density1
ClassificationMostly Clean
Inherited Risk2
Total Siblings1
Active Siblings1
Threat Siblings1

Neighboring IPs: Single active sibling detected within the /24 subnet. One threat sibling identified, indicating minimal localized risk concentration.

---

## RELATIONSHIP GRAPH

Relationship TypeCountTarget
DNS AssociationsMultiplestretchoid.com hostnames
Network AssociationsMultipleMSFT network relationships

Total Relationships: 32 relationship entries mapped.

---

## CONTROL PLANE DATA

MetricValue
Origin ASN8075
BGP Prefix20.160.0.0/12
Route StabilityFalse
Route Changes (30d)0
RPKI StateNot Evaluated
IRR ConsistencyNot Evaluated
DNSSEC ValidYes
DNSBL Listed1 of 8 total lists

---

## RECOMMENDED ACTIONS

Based on current risk profile:

1. No Blocking Recommended – IP demonstrates legitimate cloud infrastructure characteristics with low risk score.

2. Allow Traffic – Consistent Microsoft Azure hosting profile with no malicious indicators.

3. Monitor Context – Evaluate inbound traffic patterns if unexpected activity observed.

4. No Firewall Rules Required – Standard cloud egress/ingress policies apply.

---

## ANALYST NOTES

This IP represents normal Microsoft Azure cloud infrastructure operations. The single threat sibling in the /24 subnet is a localized concern but does not elevate the individual IP's risk profile. The DNS association with stretchoid.com is consistent with Microsoft's infrastructure naming conventions. No immediate defensive action required beyond standard cloud provider policies.

Confidence Level: High – Consistent infrastructure classification across multiple observation periods.

---

*Generated by IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionAZ
CityPhoenix
TimezoneAmerica/Phoenix
Latitude33.45
Longitude-112.07

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRazpdwg445sor.stretchoid.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesazpdwg445sor.stretchoid.com

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
8%
11
services
15%
22
ownership
24%
23
reputation
26%
13
geolocation
33%
23
Overall22%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-19 03:35:45 UTC
Last Seen2026-06-28 08:24:00 UTC
Profile Built2026-06-29 02:28:22 UTC
Data FreshnessLive
Signal Types22
Total Observations26
πŸ” 22 signal types Β· 26 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.