IPDebrief

20.205.229.184

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Target IP: 20.205.229.184/32

Classification: Microsoft Azure Cloud Infrastructure

Report Date: 2026-08-05

Risk Level: Moderate (65/100)

---

## EXECUTIVE SUMMARY

IP 20.205.229.184 is a Microsoft Azure cloud infrastructure address registered under Microsoft Corporation (ASN 8075) with a moderate risk score of 65/100. The IP is geolocated to Singapore and belongs to the 20.192.0.0/10 CIDR block. Despite the elevated risk score, no active threat indicators or known malicious campaigns were detected. The subnet maintains a clean classification with zero abuse density.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
OrganizationMicrosoft Corporation
Network NameMSFT
ASN8075
CountrySingapore (SG)
CIDR Block20.192.0.0/10
Infrastructure TypeCloudCompute
ProviderMicrosoft Azure

The IP operates within Microsoft's cloud infrastructure with no active open ports or services detected. DNS resolution returns no PTR hostnames, and no email authentication records (SPF, DMARC) are associated with this address.

---

## THREAT ASSESSMENT

Threat Indicators

Risk Score Breakdown

While the risk score is elevated, the absence of active threat indicators suggests the score may reflect infrastructure-based flags rather than confirmed malicious activity. The IP is classified as a cloud provider with no evidence of proxy, VPN, or hosting abuse patterns.

---

## OBSERVATION HISTORY

A total of 18 observations have been recorded for this IP address:

DateSignal TypeKey Findings
2026-08-05Cloud/InfrastructureMicrosoft Azure, non-residential
2026-08-05GeolocationSingapore (maxmind-geolite2)
2026-07-29Threat AnalysisNo banner/cert matches
2026-07-29Subnet AnalysisClean classification, 0 abuse density

Temporal analysis indicates:

---

## NETWORK RELATIONSHIPS

The relationship graph contains 5 relationships, all classified as "Same Network" pointing to Microsoft (MSFT). No external entity relationships, hostnames, organizations, or certificates were identified beyond the Microsoft infrastructure footprint.

---

## SUBNET ANALYSIS (20.205.229.0/24)

MetricValue
Abuse Density0
ClassificationClean
Total Siblings2
Active Siblings1
Threat Siblings0

Neighbor IP Analysis:

The subnet demonstrates clean characteristics with minimal risk distribution. The sole neighboring IP exhibits low-risk behavior (25/100).

---

## CONTROL PLANE DATA

MetricValue
BGP Prefix20.192.0.0/10
Origin ASN8075
Route StabilityFalse
Route Changes (30d)0
DNSSEC ValidTrue
RPKI StateNot reported

---

## RECOMMENDED ACTIONS

CategoryActionSeverity
MonitoringIncrease logging verbosity and review recent activityHigh

Firewall Rule Recommendations

iptables:

```bash

iptables -A INPUT -s 20.205.229.184 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 20.205.229.184 drop

```

nginx:

```nginx

deny 20.205.229.184;

```

Cloudflare WAF:

```json

{

"description": "Block 20.205.229.184 β€” IPDebrief risk score 65",

"action": "block",

"filter": {"expression": "ip.src eq 20.205.229.184"}

}

```

AWS WAF:

```json

{

"Addresses": ["20.205.229.184/32"],

"Description": "IPDebrief risk 65"

}

```

---

## INTELLIGENCE ASSESSMENT

This IP address represents Microsoft Azure cloud infrastructure with a moderate risk classification. The elevated risk score (65/100) is not supported by active threat indicatorsβ€”no blacklists, known attackers, spam sources, or malicious campaigns were detected. The subnet environment remains clean with zero abuse density.

Recommended Approach: Implement monitoring controls as outlined above. Given the Microsoft Azure context, consider false positive possibilities while maintaining defensive posture. The recommendation to block stems from the moderate risk score but should be evaluated against business context and additional threat intelligence sources.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
RegionSG
CitySingapore
TimezoneAsia/Singapore
Latitude1.35
Longitude103.82

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network NameMSFT
CIDR Block20.192.0.0/10
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
36%
24
routing
13%
11
services
19%
22
ownership
27%
23
reputation
32%
13
geolocation
35%
23
Overall27%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-22 01:11:35 UTC
Last Seen2026-08-12 16:34:03 UTC
Profile Built2026-08-12 16:48:49 UTC
Data FreshnessLive
Signal Types20
Total Observations21
πŸ” 20 signal types Β· 21 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.