# IP Intelligence Briefing: 20.220.15.170
Classification: Moderate Risk (Score: 65/100)
Date: 2026-08-13
Assigned: SOC Analyst
## Executive Summary
IP address 20.220.15.170 is a Microsoft Azure cloud infrastructure endpoint located in Toronto, Ontario. The IP exhibits moderate risk characteristics with elevated threat indicators, primarily attributed to DNSBL listings. No active malicious campaigns or known attacker associations were identified.
## Ownership & Network Classification
- Organization: Microsoft Corporation (AS8075)
- Network Block: 20.192.0.0/10
- Infrastructure Type: Cloud Compute (Microsoft Azure)
- Classification: Cloud Infrastructure / No Services
- Registration: ARIN (North America)
## Geolocation Data
- Country: Canada (CA)
- Region: Ontario
- City: Toronto
- Geolocation Confidence: High (geoConsensus: true, geoPlausible: true)
## Threat Assessment
The IP registered a risk score of 65/100, classified as Moderate Risk. Key indicators include:
- DNSBL Status: Listed on 3 of 8 threat intelligence feeds (severity: high)
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Campaign Association: None detected
- Abuse Confidence: No specific score provided
## Neighborhood Analysis
The /24 subnet (20.220.15.0/24) demonstrates low abuse activity:
- Subnet Abuse Density: 0 (clean classification)
- Total Neighbors: 1 (20.220.15.7, risk score: 25)
- Threat Siblings: 0
- Inherited Risk: Minimal
## Historical Observations
Seventeen total observations recorded. Most recent activity from 2026-08-13 showed:
- Location inference consistent with Toronto, ON, CA
- DNSBL listings flagged with high severity on one observation
- Operator score: 0.1304 (Minimal)
- Route stability: False (route changes detected in 30-day window)
## Technical Services
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Banner Detection: No services detected (firewalled)
## Recommended Actions
Immediate
1. Increase Logging: Enable verbose logging for traffic from this IP source
2. Firewall Policy: Apply block rule for 20.220.15.170/32
Technical Implementation
```
iptables: iptables -A INPUT -s 20.220.15.170 -j DROP
nftables: nft add rule inet filter input ip saddr 20.220.15.170 drop
nginx: deny 20.220.15.170;
```
Platform-Specific Rules
- Cloudflare WAF: Block with expression `ip.src eq 20.220.15.170`
- AWS WAF: Add address 20.220.15.170/32 to block list
- pfSense: Configure for 20.220.15.170/32
## Threat Context
The moderate risk score correlates with DNSBL listings rather than confirmed malicious activity. The IP resides within Microsoft Azure's 20.192.0.0/10 block, which hosts legitimate cloud workloads. The elevated risk likely stems from false positives or temporary abuse patterns within the broader Azure infrastructure.
## Analyst Notes
No definitive indicators of compromise or active campaigns were observed. The IP represents a Microsoft Azure endpoint with moderate risk profile due to DNSBL associations. Consider correlating with additional threat intelligence sources before implementing blocking measures, as legitimate cloud traffic may be affected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:50:09 UTC |
| Last Seen | 2026-08-13 00:16:13 UTC |
| Profile Built | 2026-08-13 00:19:38 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.