IPDebrief

20.80.88.7

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## THREAT INTELLIGENCE BRIEFING

Target: 20.80.88.7/32

Classification: Microsoft Azure Cloud Infrastructure

Risk Assessment: Moderate Risk (Score: 40/100)

Report Generated: Current Cycle

---

EXECUTIVE SUMMARY

IP 20.80.88.7 is a Microsoft Azure cloud infrastructure address located in Des Moines, IA. While the IP belongs to Microsoft's legitimate cloud network (ASN 8075, BGP prefix 20.64.0.0/10), intelligence gathering reveals anomalous DNS characteristics and blacklist associations that warrant defensive monitoring. The subnet shows low-abuse density (0.5) with one identified threat sibling.

---

OWNERSHIP & GEOSOCIAL DATA

AttributeValue
OrganizationMicrosoft Corporation
ASN8075
RIRARIN
CountryUnited States (US)
RegionIowa (IA)
CityDes Moines
Coordinates41.6°N, 93.61°W
Geo ConsensusValidated

---

NETWORK ROLE & INFRASTRUCTURE

---

THREAT INDICATORS & REPUTATION

---

DNS ANALYSIS

---

SERVICES & PORTS

---

SIGNAL OBSERVATION HISTORY

Total observations recorded: 23

Recent Activity (June 2026):

Temporal Analysis: No persistent malicious behavior observed. Average ownership duration stable.

---

NETWORK RELATIONSHIPS

---

SUBNET NEIGHBORHOOD ANALYSIS

Subnet: 20.80.88.7/24

MetricValue
Abuse Density0.5
Classificationmostly_clean
Total Siblings2
Active Siblings0
Threat Siblings1

Notable Neighbor: 20.80.88.209 (Risk Score: 25, Authority Score: 60)

---

DEFENSIVE RECOMMENDATIONS

Recommended Actions: Block traffic from this IP address based on risk profile.

Firewall Rules Generated:

---

INTELLIGENCE CONCLUSION

IP 20.80.88.7 represents Microsoft Azure cloud infrastructure with a moderate risk profile. While the IP belongs to a legitimate provider, the combination of non-Microsoft DNS resolution (stretchoid.com), two DNSBL listings, and neighborhood threat activity suggests potential misconfiguration or compromised infrastructure.

Risk Level: Monitor/Block

Confidence: Moderate

Recommended Action: Implement firewall blocking rules pending further investigation of DNS anomalies.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionIA
CityDes Moines
TimezoneAmerica/Chicago
Latitude41.60
Longitude-93.61

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network Nameβ€”
CIDR Block20.64.0.0/10
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRazpdcgevfcj8.stretchoid.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesazpdcgevfcj8.stretchoid.com

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
30%
23
services
8%
11
ownership
20%
23
reputation
28%
13
geolocation
31%
23
Overall25%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-09 17:41:26 UTC
Last Seen2026-06-27 16:09:17 UTC
Profile Built2026-06-28 10:15:00 UTC
Data FreshnessLive
Signal Types22
Total Observations27
πŸ” 22 signal types Β· 27 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.