# IP Intelligence Briefing: 20.29.23.166/32
Classification: Low Risk Cloud Infrastructure
Date: 2026-07-30
Analyst: IPDebrief SOC Team
---
## Executive Summary
IP address 20.29.23.166 is identified as Microsoft Azure cloud infrastructure with a low overall risk profile (score: 25). The address shows no active services, no known threat indicators, and belongs to a stable cloud environment. No immediate blocking or mitigation actions are recommended at this time.
---
## Risk Assessment
| Metric | Value |
|---|---|
| **Overall Risk Score** | 25 (Low Risk) |
| **Reputation** | Low Risk |
| **Abuse Confidence Score** | Not Available |
| **Blacklist Count** | 1 of 8 lists |
| **Known Attacker** | False |
| **Spam Source** | False |
| **Tor Exit Node** | False |
Risk Breakdown:
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
---
## Infrastructure Profile
Network Role: Microsoft Azure Cloud Infrastructure
ASN: 8075 (MICROSOFT-CORP-MSN-AS-BLOCK)
Location: Des Moines, Iowa, United States
CIDR Block: 20.0.0.0/11 (Azure backbone)
Infrastructure Type: Cloud Data Center
DNS Resolution:
- PTR Hostname: azpdcg9mstn5.stretchoid.com
- Forward Resolution: azpdcg9mstn5.stretchoid.com (1 hostname)
- Domain: stretchoid.com
- CAA Records: Present
---
## Threat Indicators
Current Threat Status: Clean
- Active Threat Indicators: 0
- Known Campaigns: None
- Malware/Honeypot Hits: 0
- WAF Violations: 0
- Enumeration Strikes: 0
- Total Incidents: 0
DNSBL Status: Listed on 1 of 8 DNSBL providers
---
## Network Observations (History)
Total Observations: 13 signals recorded
Timeframe: Recent monitoring window
Key Historical Signals:
- ASN 8075 (Microsoft) confirmed via multiple sources
- DNSSEC validation: Valid
- CAA records present
- One blacklist listing with "high" severity detected
- No persistent malicious behavior patterns observed
Behavioral Analysis:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 0
- Conclusion: Not persistently malicious
---
## Neighborhood Analysis (Subnet: 20.29.23.0/24)
Total Neighbors: 2
Abuse Density: 0 (Low)
| IP Address | Risk Score | Authority Score | Classification |
|---|---|---|---|
| 20.29.23.70 | 25 | 60 | Low |
| 20.29.23.130 | 25 | 60 | Low |
Risk Distribution: High: 0, Medium: 0, Low: 2
---
## Relationships
DNS Association: azpdcg9mstn5.stretchoid.com
- Single hostname association identified
- No organization or certificate relationships detected
---
## Recommended Actions
Security Posture: Monitor/Allow
Firewall Rules: None Required
Recommended Actions: No specific actions recommended
Rationale:
- Low-risk cloud infrastructure address
- No active services or ports detected
- No active threat indicators
- Part of legitimate Microsoft Azure infrastructure
- No evidence of malicious activity
---
## Intelligence Narrative
IP 20.29.23.166 represents Microsoft Azure cloud infrastructure located in Des Moines, Iowa. The address exhibits characteristics typical of cloud provider infrastructure: no open ports, minimal DNS footprint, and association with the stretchoid.com domain. Risk scoring indicates low threat potential with a score of 25.
Historical monitoring reveals 13 observations with no persistent malicious behavior patterns. The IP appears on one DNSBL list (high severity), though the overall context suggests this is likely related to infrastructure scanning rather than active abuse.
Neighbor Analysis confirms the subnet 20.29.23.0/24 maintains low abuse density with two additional sibling IPs showing identical low-risk profiles (score 25, authority 60).
Assessment: This IP should be treated as low-risk cloud infrastructure. No blocking or mitigation is warranted at this time. Continue standard monitoring practices.
---
Report Generated: IPDebrief Intelligence Platform
Data Freshness: Real-time
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.0.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdcg9mstn5.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdcg9mstn5.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 10:06:37 UTC |
| Last Seen | 2026-08-12 22:25:52 UTC |
| Profile Built | 2026-08-12 22:28:13 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.