# IP Intelligence Briefing: 20.65.195.35/32
## Executive Summary
IP 20.65.195.35 is Microsoft Azure infrastructure with a moderate risk score of 40. The IP demonstrates consistent high-abuse subnet characteristics and elevated neighborhood risk. Despite being legitimate cloud infrastructure, the combination of DNS associations and subnet abuse patterns warrants defensive consideration.
## Infrastructure Profile
- Organization: Microsoft Corporation (ASN 8075, MSFT)
- Network: 20.33.0.0/16 (MSFT)
- Geolocation: San Antonio, TX, US (America/Chicago timezone)
- Infrastructure Type: Cloud Compute (Microsoft Azure)
- Network Classification: Cloud hosting with firewalled/no services detected
- DNS Resolution: azpdsskzu25m.stretchoid.com (forward confirmed)
## Risk Assessment
| Metric | Value |
|---|---|
| Overall Risk Score | 40 (Moderate Risk) |
| Provider Score | 0 |
| Authority Score | 0 |
| DNSBL Listed | 1 of 8 lists |
| Threat Indicators | None detected |
| Is Tor Exit | No |
| Is Known Attacker | No |
| Is Spam Source | No |
## Neighborhood Analysis (20.65.195.0/24)
The /24 subnet exhibits elevated abuse characteristics:
- Abuse Density: 0.5556 (High Abuse classification)
- Total Siblings: 9
- Active Siblings: 2
- Threat Siblings: 5
- Inherited Risk: 12
All 8 neighboring IPs in the /24 show identical risk scoring (40) with authority scores of 60, indicating systemic subnet characteristics rather than isolated incidents.
## Temporal Observations (21 Total)
Historical signal tracking reveals:
- Observation Period: Multiple observations in June 2026
- Abuse Density Range: 0.5556 β 0.6667 (consistent high-abuse classification)
- Inherited Risk Range: 12 β 14
- Threat Siblings Range: 5 β 6
- Stability: Ownership and threat patterns show no significant changes over observation period
## Relationship Graph
- Network Associations: Multiple same-network relationships to MSFT
- DNS Associations: azpdsskzu25m.stretchoid.com (repeated associations)
- No certificate matches or campaign correlations detected
## Defensive Recommendations
Despite being Azure infrastructure, the elevated risk score and neighborhood abuse characteristics suggest defensive blocking is prudent:
Recommended Actions:
- Block in firewall: `iptables -A INPUT -s 20.65.195.35 -j DROP`
- Cloudflare WAF: Block with expression `ip.src eq 20.65.195.35`
- AWS WAF: Add 20.65.195.35/32 to blocked addresses
SOC Analyst Notes:
- The moderate risk score (40) combined with high-abuse subnet classification (0.5556) creates ambiguity
- Azure infrastructure typically indicates legitimate cloud compute, but the DNS hostname (stretchoid.com) and neighborhood abuse patterns suggest potential misuse
- Recommend correlating with internal telemetry for outbound connections from this IP
- Consider implementing rate limiting before full blocking to allow legitimate Azure traffic while mitigating potential abuse
Status: Monitor. Block recommended pending internal telemetry correlation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.33.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdsskzu25m.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdsskzu25m.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 19% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 10:58:46 UTC |
| Last Seen | 2026-06-29 07:39:10 UTC |
| Profile Built | 2026-06-29 07:44:01 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.