# IP Intelligence Briefing: 20.64.104.65/32
Classification: Moderate Risk Cloud Infrastructure Asset
Report Date: Based on current data snapshot
Risk Score: 40/100
## Executive Summary
IP 20.64.104.65 is a Microsoft Azure cloud compute endpoint located in Boston, Massachusetts, US (ASN 8075). The IP presents moderate risk (score 40) due to DNS blacklist associations and route instability, but operates within a predominantly clean subnet environment. No active malicious services or open ports were detected during scanning.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 |
| **Reputation** | Moderate Risk |
| **ASN** | 8075 (Microsoft Corporation) |
| **Location** | Boston, MA, US |
| **Infrastructure** | CloudCompute (Microsoft Azure) |
| **Network Role** | Firewalled / No Services |
| **Subnet** | 20.64.104.65/24 |
## Threat Indicators
DNS Blacklist Activity:
- Listed on 8 DNSBLs with 2 active listings
- Maximum severity rating: High
- DNS entry resolves to: azpdsgkml0gq.stretchoid.com
Network Control Plane:
- Route stability flagged as unstable (isRouteStable: false)
- Origin ASN 8075 with BGP prefix 20.64.0.0/10
- Traceroute completed 30 hops through Comcast transit network
## Observation History
Analysis of 17 signal observations revealed the following pattern:
- Recent Microsoft Corporation ownership confirmed in August 2026 observations
- Geographic signals consistently mapped to Boston, MA region
- DNS blacklist detections appeared in recent observation window
- No evidence of persistent malicious behavior or campaign correlation
## Neighborhood Context
Subnet Analysis: 20.64.104.65/24
- Total sibling IPs: 16
- Abuse density: 0.1765 (17.65%)
- Classification: Mostly clean
- Risk distribution within subnet: 0 high-risk, 3 medium-risk, 13 low-risk IPs
Several neighboring IPs shared similar risk scores (25-40), indicating distributed cloud infrastructure rather than concentrated abuse.
## Relationship Graph
- DNS Association: azpdsgkml0gq.stretchoid.com (hostname)
- No additional organizational or certificate relationships identified
## Recommended Actions
For SOC Operations:
1. Monitor DNS blacklist status on stretchoid.com domain
2. No immediate blocking recommendedβIP operates on Microsoft Azure infrastructure with firewalled services
3. Evaluate context of traffic against internal threat intelligence
4. Consider subnet-level monitoring given 17.65% abuse density in /24
Firewall Considerations:
- No explicit block/restrict recommended based on current risk profile
- Cloud infrastructure classification suggests legitimate enterprise traffic patterns
- DNSBL presence warrants monitoring but not definitive malicious indicator
## Conclusion
20.64.104.65 represents a Microsoft Azure cloud endpoint with moderate risk indicators primarily stemming from DNS blacklist associations. The IP shows no evidence of active malicious services, open ports, or known attack campaigns. Contextual assessment within the subnet indicates legitimate cloud infrastructure deployment. SOC teams may monitor DNSBL status but need not initiate blocking actions without additional corroborating threat intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.33.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdsgkml0gq.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdsgkml0gq.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 31% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 28% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-11 11:49:40 UTC |
| Last Seen | 2026-08-31 21:24:04 UTC |
| Profile Built | 2026-08-31 21:27:50 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 30 |
Full dossier details are available via our API.