IPDebrief

20.221.72.95

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 20.221.72.95/32

Date: Current

Classification: LOW RISK - Microsoft Azure Infrastructure

---

## EXECUTIVE SUMMARY

IP address 20.221.72.95 is identified as Microsoft Corporation cloud infrastructure (MSFT, ASN 8075) with a low-risk profile (risk score: 25). No active threat indicators, blacklisting, or malicious activity detected. The IP belongs to Microsoft Azure's cloud compute infrastructure in the Des Moines, Iowa region.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**Organization**Microsoft Corporation
**ASN**8075
**Network**MSFT
**CIDR Block**20.192.0.0/10
**Geolocation**US, Des Moines, IA
**Network Role**Microsoft Azure (Cloud Compute)
**Classification**Cloud Infrastructure

---

## THREAT ASSESSMENT

Current Risk Profile

Service Analysis

---

## OBSERVATION HISTORY

Total Observations: 21 signals

Recent Signal Activity:

Temporal Analysis:

---

## RELATIONSHIP GRAPH

Primary Associations:

The IP maintains consistent associations within Microsoft's network infrastructure with DNS resolution pointing to Microsoft's stretchoid.com domain infrastructure.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 20.221.72.95/24

Abuse Density: 0.0 (mostly clean)

Total Siblings: 2

Active Siblings: 1

Threat Siblings: 1

Neighbor IP: 20.221.72.102

The immediate neighborhood shows minimal threat activity with one threat sibling requiring monitoring.

---

## SECURITY RECOMMENDATIONS

Recommended Actions: None required

Risk-Based Guidance:

Monitoring Priority: LOW

---

## INTELLIGENCE CONCLUSION

This IP address represents legitimate Microsoft Azure cloud infrastructure with no malicious indicators. The low risk score, clean blacklist status, and absence of active threat signals support continued operational monitoring without immediate defensive action. The single threat sibling in the /24 neighborhood (20.221.72.102) warrants periodic review but does not change the assessment of 20.221.72.95 as benign infrastructure.

Recommendation: No action required. Maintain standard monitoring for Microsoft cloud infrastructure.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionIA
CityDes Moines
TimezoneAmerica/Chicago
Latitude41.60
Longitude-93.61

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network NameMSFT
CIDR Block20.192.0.0/10
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRazpdcs2hmrfa.stretchoid.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesazpdcs2hmrfa.stretchoid.com

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
36%
24
routing
13%
11
services
21%
22
ownership
30%
23
reputation
28%
13
geolocation
27%
23
Overall26%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-06-04 06:35:43 UTC
Last Seen2026-06-21 11:16:08 UTC
Profile Built2026-06-21 11:21:20 UTC
Data FreshnessLive
Signal Types23
Total Observations26
πŸ” 23 signal types Β· 26 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.