# Intelligence Briefing: 20.65.193.104
Classification: Low Risk / Legitimate Cloud Infrastructure
Date: 2026-08-05
Analyst: IPDebrief Intelligence Platform
---
## Executive Summary
IP 20.65.193.104 is identified as Microsoft Azure cloud infrastructure with a low-risk profile (score: 25). The address shows no malicious indicators, no blacklist associations, and operates within a predominantly clean /24 subnet. No security action is recommended at this time.
---
## Network Profile
| Attribute | Value |
|---|---|
| **IP Address** | 20.65.193.104/32 |
| **Risk Score** | 25 (Low Risk) |
| **Organization** | Microsoft Corporation (AS8075) |
| **Network Name** | MSFT |
| **CIDR Block** | 20.33.0.0/16 |
| **Geolocation** | San Antonio, TX, US |
| **Network Role** | Cloud Compute (Microsoft Azure) |
| **Reputation** | Low Risk |
---
## Technical Indicators
DNS Resolution:
- PTR Record: azpdssd7wq2x.stretchoid.com
- Forward Resolution: Confirmed
- DNS Classification: Microsoft Azure Internal DNS
Network Classification:
- Is Cloud: Yes
- Is CDN: No
- Is Hosting: Yes
- Is Mobile/Residential: No
- Is Bogon: No
Threat Indicators:
- Blacklist Count: 0
- Abuse Confidence Score: N/A
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Campaign Likelihood: None
Services:
- Open Ports: None detected
- HTTP/TLS: No active services
---
## Neighborhood Analysis
Subnet: 20.65.193.0/24
- Total Siblings: 29 IPs
- Active Siblings: 17
- Threat Siblings: 4
- Abuse Density: 0 (0%)
- Classification: Mostly Clean
Risk Distribution:
- High Risk: 0
- Medium Risk: 4
- Low Risk: 21
Notable neighbors with elevated scores:
- 20.65.193.108: Risk 40
- 20.65.193.158: Risk 40
- 20.65.193.159: Risk 40
- 20.65.193.203: Risk 50
---
## Observation History
Total Observations: 20 signals collected
Time Range: 2026-07-30 to 2026-08-05
Threat Persistence: 0 days
Ownership Changes: 0
Recent signal observations indicate:
- Operator Score: 0.3478 (Basic)
- DNSSEC: Valid
- Control Plane: Route stability issues noted
- No persistent malicious behavior detected
---
## Relationship Graph
Primary Relationships:
- DNS Association: azpdssd7wq2x.stretchoid.com (multiple entries)
- Network Association: MSFT (Microsoft Azure network)
- Total Relationships: 14
The IP exhibits standard Microsoft Azure infrastructure patterns with consistent DNS and network associations.
---
## Recommended Actions
Current Risk Level: 25 (Low)
Recommended Action: Monitor / Allow
No specific firewall rules or blocking recommendations are warranted. The IP represents legitimate Microsoft Azure cloud infrastructure with no observed malicious activity.
Rule Recommendation:
- No iptables/nftables rules required
- No WAF rules required
- Standard cloud traffic handling appropriate
---
## Intelligence Assessment
The IP address 20.65.193.104 is classified as low-risk Microsoft Azure infrastructure. Key assessment points:
1. Legitimate Cloud Provider: Confirmed Microsoft Azure ownership with AS8075
2. Clean Threat Profile: Zero blacklist hits, no known campaigns, no abuse indicators
3. Stable Infrastructure: No ownership changes, consistent DNS resolution
4. Low Neighborhood Risk: Subnet classified as "mostly clean" with 72% low-risk siblings
5. No Active Threats: Services show as "firewalled/no services" with no open ports
SOC Analyst Guidance: Treat as benign cloud infrastructure. No blocking or alerting required. Continue standard monitoring practices for Microsoft Azure traffic.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.33.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdssd7wq2x.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdssd7wq2x.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 20% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 08:45:18 UTC |
| Last Seen | 2026-08-12 19:27:33 UTC |
| Profile Built | 2026-08-12 19:38:55 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.