# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 9.205.16.190/32
Classification: Cloud Infrastructure / Moderate Risk
Date: Current (Latest signals: 2026-08-05)
## EXECUTIVE SUMMARY
IP 9.205.16.190 is a Microsoft Azure cloud compute instance located in Copenhagen, Denmark. The address carries a moderate risk score of 50 and is associated with ASN 8075 (Microsoft Corporation). While the subnet shows no active abuse density, the IP exhibits route instability and historical threat indicators. The single open RDP service port (3389/tcp) warrants attention in cloud security contexts.
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| ASN | 8075 (Microsoft Azure) |
| Organization | Divya Quamara |
| Network | 9.205.0.0/17 |
| Country | Denmark (DK) |
| City | Copenhagen |
| Infrastructure Type | Cloud Compute |
| Classification | Hosting / Single-Service Host |
## THREAT INDICATORS
- Risk Score: 50 (Moderate)
- Blacklist Status: Listed on 2 DNSBL lists
- Operator Score: 0.2174 (Minimal)
- Known Campaigns: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
## NETWORK BEHAVIOR
- Route Stability: Unstable (2 route changes in last 30 days)
- BGP Path: 7018 โ 8075
- Open Services: TCP 3389 (RDP)
- DNS Resolution: No forward resolution confirmed
- Historical Geolocation: Primary consensus: Copenhagen, Denmark; one historical observation noted United States geolocation with threat indicators
## OBSERVATION HISTORY
Total signals observed: 22
Recent Activity:
- 2026-08-05: Minimal operator score (0.25), 3 signals detected
- 2026-07-30: BGP route changes detected (2 total in 30-day window)
Notable Signals:
- 2026-08-05: Threat indicator from AlienVault OTX (US geolocation, reputation score 0, threats present)
- Route stability flag: false (prefix 9.205.0.0/16)
## NEIGHBORHOOD ANALYSIS
Subnet: 9.205.16.190/24
- Abuse Density: 0%
- Active Siblings: 0
- Threat Siblings: 0
- Classification: Clean
- Total Neighbors: 0
## RELATIONSHIP GRAPH
9 relationships identified, all categorized as "Same Network" (cloud infrastructure). No external relationships to organizations, hostnames, or certificates detected.
## RECOMMENDATIONS
Action Status: Probabilistic (requires validation against additional signals)
Suggested Firewall Rules:
- iptables: `iptables -A INPUT -s 9.205.16.190 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 9.205.16.190 drop`
- Cloudflare WAF: Block with expression `ip.src eq 9.205.16.190`
- AWS WAF: Address `9.205.16.190/32`
Contextual Assessment:
The IP's moderate risk score is primarily driven by cloud infrastructure hosting patterns and route instability. The historical AlienVault OTX threat indicator and DNSBL listings warrant monitoring, but the IP operates within legitimate Microsoft Azure infrastructure. If blocking is required, consider the following:
1. Verify if this IP is targeted or originated in incidents
2. Assess whether RDP exposure is intentional for legitimate services
3. Monitor for changes in threat indicators over subsequent observation windows
Priority: Medium โ Monitor for escalation in threat indicators or changes in network behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 9.205.0.0/17 |
| RIR | ARIN |
| Country | DK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 30% | 11 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:34:41 UTC |
| Last Seen | 2026-08-12 23:36:59 UTC |
| Profile Built | 2026-08-12 23:50:28 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.