# IP INTELLIGENCE BRIEFING: 74.7.242.33/32
## Executive Summary
IP address 74.7.242.33 is a Microsoft Azure cloud infrastructure endpoint located in Atlanta, Georgia with a moderate risk profile (50/100). The IP shows no active threat indicators but is listed on 2 of 8 DNSBLs and exhibits some network-level anomalies requiring monitoring.
## Infrastructure Profile
- ASN: 8075 (Microsoft Azure)
- Organization: Divya Quamara
- CIDR Block: 74.7.128.0/17
- Infrastructure Type: Cloud Compute
- Geolocation: US, Georgia, Atlanta (validated with 2 geo sources)
- Network Role: Cloud-hosted with no services exposed (firewalled)
## Risk Assessment
- Overall Risk Score: 50 (Moderate Risk)
- Threat Indicators: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 direct blacklists; 2 DNSBL listings
## Network Context
The /24 subnet (74.7.242.0/24) contains 21 sibling IPs with an abuse density of 0.1429. Risk distribution shows 18 low-risk neighbors, 2 medium-risk, and 0 high-risk IPs. Three threat siblings were identified in the neighborhood, suggesting some lateral risk.
## Historical Observations
Analysis of 22 observation signals reveals:
- Recent Activity: August 2026 signals showing minimal operator risk (0.1304)
- Geolocation Variance: July 2026 observations showed conflicting geolocation data (Boston, MA vs. Atlanta, GA), indicating potential routing inconsistencies
- Routing Path: 29-hop traceroute via Comcast networks with no successful target reach
- Alienvault OTX: One signal from AS17184 (Fusion Communications) with threat-associated pulses
## DNS and Service Analysis
- Open Ports: None detected
- DNS Records: No PTR hostnames; forward resolution failed
- Email Authentication: No SPF or DMARC records
- HTTPS: No TLS certificates or HTTP services running
- HTTP Status: No response (service not accessible or filtered)
## Recommended Actions
1. Monitor for Service Changes: The IP is currently firewalled with no open services. Any change in service exposure warrants investigation.
2. DNSBL Review: Investigate the 2 DNSBL listings to understand listing rationale and potential reputation impact.
3. Subnet Monitoring: The presence of 3 threat siblings in the /24 subnet suggests monitoring adjacent IP addresses for coordinated malicious activity.
4. Geolocation Validation: Continue monitoring for geolocation inconsistencies that may indicate routing manipulation or infrastructure changes.
5. Allow with Logging: Given the moderate risk score and cloud infrastructure nature, allow traffic with enhanced logging and anomaly detection.
## Threat Intelligence Classification
- Classification: Cloud Infrastructure Endpoint
- Campaign Likelihood: None
- Campaign Matches: 0
- Correlated IPs: 0
- Cert Matches: 0
## SOC Analyst Notes
This IP represents legitimate Microsoft Azure cloud infrastructure. The moderate risk score stems from DNSBL listings and neighborhood context rather than direct malicious indicators. Focus monitoring efforts on the subnet's threat siblings and any service exposure changes rather than treating this IP as a primary threat actor.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 74.7.128.0/17 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 23:21:01 UTC |
| Last Seen | 2026-08-13 01:15:59 UTC |
| Profile Built | 2026-08-13 01:24:47 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.