# IP INTELLIGENCE BRIEFING
Target: 20.221.72.95/32
Date: Current
Classification: LOW RISK - Microsoft Azure Infrastructure
---
## EXECUTIVE SUMMARY
IP address 20.221.72.95 is identified as Microsoft Corporation cloud infrastructure (MSFT, ASN 8075) with a low-risk profile (risk score: 25). No active threat indicators, blacklisting, or malicious activity detected. The IP belongs to Microsoft Azure's cloud compute infrastructure in the Des Moines, Iowa region.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | Microsoft Corporation |
| **ASN** | 8075 |
| **Network** | MSFT |
| **CIDR Block** | 20.192.0.0/10 |
| **Geolocation** | US, Des Moines, IA |
| **Network Role** | Microsoft Azure (Cloud Compute) |
| **Classification** | Cloud Infrastructure |
---
## THREAT ASSESSMENT
Current Risk Profile
- Risk Score: 25/100 (Low Risk)
- Abuse Confidence: None
- Blacklist Status: Clean (0 blacklists)
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Service Analysis
- Open Ports: None detected
- DNS Resolution: azpdcs2hmrfa.stretchoid.com
- HTTP/TLS Services: None active
- Infrastructure Type: Cloud Compute, Firewalled
---
## OBSERVATION HISTORY
Total Observations: 21 signals
Recent Signal Activity:
- Port scanning detection (confidence: 70%)
- Neighborhood abuse density assessment (confidence: 40%)
- Ownership stability verification (confidence: 85%)
- Threat list enumeration (confidence: 20%)
- Operator score evaluation (score: 0.3478, label: Basic)
Temporal Analysis:
- Ownership changes: 0
- Threat persistence days: 0
- Persistently malicious: No
- Threat observation count: 1
---
## RELATIONSHIP GRAPH
Primary Associations:
- Network: MSFT (21 occurrences)
- DNS Hostname: azpdcs2hmrfa.stretchoid.com (multiple DNS associations)
The IP maintains consistent associations within Microsoft's network infrastructure with DNS resolution pointing to Microsoft's stretchoid.com domain infrastructure.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 20.221.72.95/24
Abuse Density: 0.0 (mostly clean)
Total Siblings: 2
Active Siblings: 1
Threat Siblings: 1
Neighbor IP: 20.221.72.102
- Risk Score: 25
- Authority Score: 60
- Classification: Low risk
The immediate neighborhood shows minimal threat activity with one threat sibling requiring monitoring.
---
## SECURITY RECOMMENDATIONS
Recommended Actions: None required
Risk-Based Guidance:
- The IP is classified as Microsoft Azure cloud infrastructure with no active threat indicators
- No firewall rules or blocking recommendations necessary
- Continue standard monitoring procedures for cloud infrastructure
Monitoring Priority: LOW
---
## INTELLIGENCE CONCLUSION
This IP address represents legitimate Microsoft Azure cloud infrastructure with no malicious indicators. The low risk score, clean blacklist status, and absence of active threat signals support continued operational monitoring without immediate defensive action. The single threat sibling in the /24 neighborhood (20.221.72.102) warrants periodic review but does not change the assessment of 20.221.72.95 as benign infrastructure.
Recommendation: No action required. Maintain standard monitoring for Microsoft cloud infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdcs2hmrfa.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdcs2hmrfa.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-04 06:35:43 UTC |
| Last Seen | 2026-06-21 11:16:08 UTC |
| Profile Built | 2026-06-21 11:21:20 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.