## IP Intelligence Briefing: 20.221.72.174
Classification: Microsoft Azure Cloud Infrastructure
Executive Summary
IP 20.221.72.174 is identified as Microsoft Azure cloud infrastructure with a low-risk profile (Risk Score: 25). The IP belongs to Microsoft Corporation (ASN 8075) within the 20.192.0.0/10 CIDR block, located in Des Moines, IA. Current threat indicators show no active malicious activity, though historical signals indicate occasional proxy detection from third-party services.
Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Network Role** | Microsoft Azure CloudCompute |
| **Infrastructure Type** | Cloud |
| **Geolocation** | United States, Iowa, Des Moines |
| **ASN** | AS8075 (Microsoft Corporation) |
| **DNS PTR** | azpdcsj408fw.stretchoid.com |
| **Open Ports** | None (Firewalled) |
| **Blacklist Count** | 0 |
Threat Analysis
Current threat indicators reveal no active malicious behavior:
- Known Campaigns: None detected
- Threat Feeds: No matches
- Reputation Sources: None flagged
- DNS Blacklists: 0 current listings (historical total: 8)
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
The IP exhibits firewalled behavior with no open services, consistent with legitimate Azure infrastructure.
Historical Observations
Analysis of 24 historical observations indicates:
- Observation Period: 24 total signals recorded
- Recent Activity: Observations from 2026-08-13 showed mixed signals
- Conflicting Indicators: ProxyCheck.io flagged the IP as "Compromised Server" (Risk: 66) on 2026-08-13, but this is an external reputation signal that does not align with the IP's core classification
- Threat Persistence: No persistent malicious pattern detected
- Ownership Stability: No ownership changes recorded
Network Neighborhood
The /24 subnet (20.221.72.0/24) maintains a clean abuse density profile:
| Metric | Value |
|---|---|
| **Abuse Density** | 0% |
| **Subnet Classification** | Clean |
| **Active Siblings** | 2 of 3 |
| **Threat Siblings** | 0 |
| **Neighbor Risk Scores** | 25 (both low risk) |
Sibling IPs include 20.221.72.95 and 20.221.72.102, both classified as low risk with authority scores of 60.
Entity Relationships
The IP maintains 14 documented relationships:
- Network Associations: Microsoft (MSFT) network
- DNS Associations: azpdcsj408fw.stretchoid.com hostname
- Organization: Microsoft Corporation
All relationships confirm Microsoft infrastructure ownership.
Recommended Actions
Based on current risk assessment (Risk Score: 25), no immediate blocking actions are recommended. However, SOC analysts should:
1. Monitor External Reputation Signals: The conflicting proxy detection from proxycheck-io warrants continued monitoring but does not justify immediate action
2. Allow Traffic: Microsoft Azure IPs are frequently legitimate sources for cloud services, email, and API traffic
3. No Firewall Rules: No specific firewall rules generated at this risk level
Assessment Conclusion
IP 20.221.72.174 represents standard Microsoft Azure cloud infrastructure. The low risk score, clean neighborhood profile, and absence of active threat indicators support classification as legitimate infrastructure. The occasional proxy detection signals are external reputation noise and do not reflect the IP's actual behavior. Continue monitoring but no action required at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdcsj408fw.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdcsj408fw.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-31 19:32:48 UTC |
| Last Seen | 2026-08-13 01:49:49 UTC |
| Profile Built | 2026-08-13 02:04:36 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.