IPDebrief

20.237.221.211

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Target: 20.237.221.211/32

Classification: Cloud Infrastructure (Microsoft Azure)

Date: 2026-07-30

---

## EXECUTIVE SUMMARY

IP 20.237.221.211 is a Microsoft Azure cloud compute resource located in Boston, MA. The asset maintains a low-risk profile (Score: 25) with no active threat indicators. The IP is listed on one DNSBL with high severity classification. No open ports or services are exposed; the system is fully firewalled. No relationships or neighboring threats were identified in the /24 subnet.

---

## INFRASTRUCTURE PROFILE

AttributeValue
**ASN**8075 (MICROSOFT-CORP-MSN-AS-BLOCK)
**Organization**Microsoft Corporation, US
**BGP Prefix**20.192.0.0/10
**Location**Boston, MA, US (America/New_York)
**Infrastructure Type**Cloud Compute (Microsoft Azure)
**Network Role**Firewalled / No Services
**Cloud Provider**Microsoft Azure
**DNSSEC Valid**Yes
**Open Ports**None detected

---

## THREAT ASSESSMENT

Overall Risk Score: 25 (Low Risk)

Abuse Confidence: Not scored

Blacklist Status: Listed on 1 of 8 DNSBLs (High Severity)

Tor Exit Node: No

Known Attacker: No

Spam Source: No

Campaign Association: None detected

Threat Indicators:

---

## OBSERVATION HISTORY

Total Observations: 9 signals

Most Recent: 2026-07-30 02:03 UTC

Key Historical Signals:

Temporal Analysis: No persistent malicious behavior detected. Threat observation count: 0. IP not classified as persistently malicious.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 20.237.221.211/24

Abuse Density: 0

Threat Siblings: 0

Active Siblings: 0

High/Medium/Low Risk Neighbors: 0/0/0

No neighboring threats identified in the /24 subnet.

---

## RELATIONSHIP GRAPH

Connected Entities: 0

No relationships detected to subnets, hostnames, organizations, or certificates.

---

## RECOMMENDED ACTIONS

Risk Score: 25 (Low)

Action Priority: Monitor

Recommendations:

---

## INTELLIGENCE NARRATIVE

IP 20.237.221.211 operates as a Microsoft Azure cloud compute resource within the 20.192.0.0/10 address space. The infrastructure demonstrates stable Microsoft ownership with consistent geolocation data from Boston, MA. Despite listing on one DNSBL with high severity, the overall risk assessment remains low (25), consistent with cloud infrastructure that may appear on security research blocklists.

No services or ports are exposed; the system is firewalled. No threat indicators, campaigns, or relationships were detected. The neighborhood shows zero abuse density, indicating this IP is not part of a coordinated threat cluster.

SOC Analyst Guidance: Treat as low-risk cloud infrastructure. No immediate action required. Monitor DNSBL listing status and maintain standard cloud resource monitoring procedures.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionCA
CitySan Francisco
TimezoneAmerica/Los_Angeles
Latitude37.78
Longitude-122.42

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network NameMSFT
CIDR Block20.192.0.0/10
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
17%
12
geolocation
27%
22
Overall22%1013
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-25 02:41:47 UTC
Last Seen2026-08-12 19:12:49 UTC
Profile Built2026-08-12 19:14:47 UTC
Data FreshnessLive
Signal Types18
Total Observations20
πŸ” 18 signal types Β· 20 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.