# IP Intelligence Briefing: 9.205.104.136
Classification: Moderate Risk (Score: 40/100)
Date: 2026-06-27
Analysis Type: Full Threat Intelligence Assessment
## Executive Summary
IP address 9.205.104.136 is identified as Microsoft Azure cloud infrastructure located in Copenhagen, Denmark (ASN 8075). The IP carries a moderate risk score of 40 with no active threat indicators present. The address shows consistent cloud infrastructure behavior over the observation period, though DNSBL listings indicate prior reputation issues.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | Microsoft Azure |
| **ASN** | 8075 |
| **Country** | DK (Denmark) |
| **City** | Copenhagen |
| **Infrastructure Type** | CloudCompute |
| **Hosting** | Yes |
| **Cloud Provider** | Microsoft Azure |
| **Network Role** | Firewalled / No Services |
## Threat Indicators
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Threat Indicators: None
- Associated Campaigns: None
## Network Behavior
- BGP Origin: 9.205.0.0/16
- AS Path: 49788 โ 8075
- Route Stability: Stable
- Open Ports: None detected
- Services: None exposed (firewalled)
- DNS Resolution: No PTR records, no forward resolution
## Neighborhood Assessment (9.205.104.0/24)
- Abuse Density: 1 (Profile) / 0 (Neighbors tool)
- Classification: Mostly Clean
- Threat Siblings: 1
- Active Siblings: 1
- Total Siblings: 1
## Historical Observations
21 observations recorded since initial detection. Signals consistently identify the IP as Microsoft Azure cloud infrastructure. Route stability maintained through AS8075 origin. No significant behavioral changes observed over the observation period.
## Recommended Actions
Risk-Based Recommendations: No specific recommendations based on current profile.
Blocking Rules (if required based on organizational policy):
- iptables: `iptables -A INPUT -s 9.205.104.136 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 9.205.104.136 drop`
- nginx: `deny 9.205.104.136;`
- pfSense: `9.205.104.136/32`
- Cloudflare WAF: Block with expression `ip.src eq 9.205.104.136`
- AWS WAF: Include 9.205.104.136/32 in block list
## Intelligence Notes
1. Cloud Infrastructure Context: IP operates within Microsoft Azure cloud environment. Cloud-based IPs often exhibit higher risk scores due to shared infrastructure with potentially abusive activities.
2. DNSBL Listings: The IP appears on 2 of 8 DNSBLs, suggesting prior association with suspicious activity. However, no current threat indicators are present.
3. Moderate Risk Profile: Score of 40 indicates moderate concern. Monitoring recommended for emerging threats.
4. No Active Threats: No open services, no threat indicators, and no known malicious campaigns associated with this IP.
Assessment: This IP represents cloud infrastructure with moderate risk due to DNSBL listings. No immediate threat action required unless organizational policy mandates blocking all Azure IPs or DNSBL-listed addresses. Monitor for behavioral changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | โ |
| CIDR Block | 9.205.0.0/16 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 24% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 11 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 21:56:00 UTC |
| Last Seen | 2026-06-27 22:16:28 UTC |
| Profile Built | 2026-06-28 16:21:16 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.