# IP Intelligence Briefing: 48.192.92.28/32
Date: 2026-06-22
Classification: Moderate Risk
Risk Score: 50/100
---
## Executive Summary
IP address 48.192.92.28 is a Microsoft Azure cloud infrastructure endpoint located in the US (Boston, MA). The IP exhibits moderate risk characteristics with 2 DNSBL listings and shows no active threat indicators. The address operates within a cloud computing environment with multiple neighbors in the /24 subnet displaying medium-risk profiles.
---
## Profile Overview
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate Risk) |
| **ASN** | 8075 (Microsoft Azure) |
| **Organization** | Divya Quamara |
| **CIDR Block** | 48.192.0.0/16 |
| **Country** | United States (US) |
| **Region** | Massachusetts (US-MA) |
| **Infrastructure Type** | CloudCompute |
| **Cloud Provider** | Microsoft Azure |
---
## Network Classification
- Cloud Infrastructure: Yes
- Cdn/Proxy/VPN: No
- Tor Exit Node: No
- Hosting Service: Yes
- Mobile/Residential: No
- Bogon Address: No
---
## Threat Indicators
- Known Campaigns: None identified
- Threat Feeds: No active indicators
- Blacklist Count: 0
- Abuse Confidence Score: Not available
- Is Known Attacker: No
- Is Spam Source: No
---
## DNS & Control Plane
- PTR Hostnames: None
- Forward Resolution: Unconfirmed
- DNSSEC Valid: Yes
- DNSBL Listed: 2 of 8 total lists
- Origin ASN: 8075
- BGP Prefix: 48.192.0.0/12
- Route Stability: False
---
## Service Exposure
- Open Ports: None detected
- TLS Certificate: None
- HTTP Service: None
- Banner Grab: None
---
## Historical Observations
12 observations recorded across the monitoring period. Recent signals indicate:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 0
- DNSSEC valid: True
- Geographic consensus shows Redmond, WA and Boston, MA
No persistent malicious behavior detected.
---
## Network Neighborhood Analysis
Subnet: 48.192.92.28/24
Total Neighbors: 13
Risk Distribution: 10 Medium, 3 Low, 0 High
Abuse Density: 0
Notable neighbor risk scores:
- 48.192.92.16: 25 (Medium)
- 48.192.92.26: 50 (Moderate)
- 48.192.92.29: 50 (Moderate)
- 48.192.92.31: 50 (Moderate)
The subnet exhibits low overall abuse density, consistent with cloud infrastructure patterns.
---
## Relationships
- Same Network: cloud (Microsoft Azure network classification)
---
## Recommended Security Actions
Based on risk profile (Score: 50), the following blocking rules are recommended:
Firewall Rules:
- `iptables -A INPUT -s 48.192.92.28 -j DROP`
- `nft add rule inet filter input ip saddr 48.192.92.28 drop`
- `nginx: deny 48.192.92.28;`
- `pfSense: 48.192.92.28/32`
- `Cloudflare WAF: Block β IPDebrief risk score 50`
- `AWS WAF: Addresses: ["48.192.92.28/32"]`
---
## Traceroute Analysis
- Hop Count: 23
- First Hop RTT: 0.2ms
- Last Hop RTT: 87.4ms
- Timeout Hops: 6
- Transit Network: Comcast
---
## Intelligence Assessment
This IP represents standard Microsoft Azure cloud infrastructure with moderate risk scoring primarily driven by DNSBL associations. No active threat campaigns, malicious scans, or known attack indicators are associated with this address. The IP operates within a /24 subnet containing 13 sibling addresses with predominantly medium-risk profiles.
Recommended Action: Monitor or block based on organizational policy. No immediate threat indicators warrant emergency response. Correlate with additional telemetry before implementing permanent blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 48.192.0.0/16 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 0% | 0 | 0 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-21 00:08:52 UTC |
| Last Seen | 2026-06-22 18:53:40 UTC |
| Profile Built | 2026-06-22 04:51:58 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.