IPDebrief

20.29.23.166

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 20.29.23.166/32

Classification: Low Risk Cloud Infrastructure

Date: 2026-07-30

Analyst: IPDebrief SOC Team

---

## Executive Summary

IP address 20.29.23.166 is identified as Microsoft Azure cloud infrastructure with a low overall risk profile (score: 25). The address shows no active services, no known threat indicators, and belongs to a stable cloud environment. No immediate blocking or mitigation actions are recommended at this time.

---

## Risk Assessment

MetricValue
**Overall Risk Score**25 (Low Risk)
**Reputation**Low Risk
**Abuse Confidence Score**Not Available
**Blacklist Count**1 of 8 lists
**Known Attacker**False
**Spam Source**False
**Tor Exit Node**False

Risk Breakdown:

---

## Infrastructure Profile

Network Role: Microsoft Azure Cloud Infrastructure

ASN: 8075 (MICROSOFT-CORP-MSN-AS-BLOCK)

Location: Des Moines, Iowa, United States

CIDR Block: 20.0.0.0/11 (Azure backbone)

Infrastructure Type: Cloud Data Center

DNS Resolution:

---

## Threat Indicators

Current Threat Status: Clean

DNSBL Status: Listed on 1 of 8 DNSBL providers

---

## Network Observations (History)

Total Observations: 13 signals recorded

Timeframe: Recent monitoring window

Key Historical Signals:

Behavioral Analysis:

---

## Neighborhood Analysis (Subnet: 20.29.23.0/24)

Total Neighbors: 2

Abuse Density: 0 (Low)

IP AddressRisk ScoreAuthority ScoreClassification
20.29.23.702560Low
20.29.23.1302560Low

Risk Distribution: High: 0, Medium: 0, Low: 2

---

## Relationships

DNS Association: azpdcg9mstn5.stretchoid.com

---

## Recommended Actions

Security Posture: Monitor/Allow

Firewall Rules: None Required

Recommended Actions: No specific actions recommended

Rationale:

---

## Intelligence Narrative

IP 20.29.23.166 represents Microsoft Azure cloud infrastructure located in Des Moines, Iowa. The address exhibits characteristics typical of cloud provider infrastructure: no open ports, minimal DNS footprint, and association with the stretchoid.com domain. Risk scoring indicates low threat potential with a score of 25.

Historical monitoring reveals 13 observations with no persistent malicious behavior patterns. The IP appears on one DNSBL list (high severity), though the overall context suggests this is likely related to infrastructure scanning rather than active abuse.

Neighbor Analysis confirms the subnet 20.29.23.0/24 maintains low abuse density with two additional sibling IPs showing identical low-risk profiles (score 25, authority 60).

Assessment: This IP should be treated as low-risk cloud infrastructure. No blocking or mitigation is warranted at this time. Continue standard monitoring practices.

---

Report Generated: IPDebrief Intelligence Platform

Data Freshness: Real-time

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionIA
CityDes Moines
TimezoneAmerica/Chicago
Latitude41.88
Longitude-93.10

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network NameMSFT
CIDR Block20.0.0.0/11
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRazpdcg9mstn5.stretchoid.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesazpdcg9mstn5.stretchoid.com

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
40%
25
routing
13%
11
services
19%
22
ownership
27%
23
reputation
26%
13
geolocation
27%
23
Overall25%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-28 10:06:37 UTC
Last Seen2026-08-12 22:25:52 UTC
Profile Built2026-08-12 22:28:13 UTC
Data FreshnessLive
Signal Types21
Total Observations24
πŸ” 21 signal types Β· 24 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.