# IP INTELLIGENCE BRIEFING: 104.211.76.60
Classification: LOW RISK โ Cloud Infrastructure (Microsoft Azure)
Report Date: 2026-06-15
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 104.211.76.60/32 is a Microsoft Azure cloud infrastructure endpoint located in Pune, India (ASN 8075). The address registers a low-risk profile (score 25) with no active threat indicators, blacklist entries, or malicious behavior patterns. Network classification confirms hosting/infrastructure role with no services exposed.
---
## Key Findings
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Organization** | Microsoft Corporation |
| **ASN** | 8075 |
| **Country** | India (IN) |
| **City** | Pune |
| **Infrastructure Type** | CloudCompute (Azure) |
| **Reputation** | Low Risk |
| **Blacklist Count** | 0 |
| **Threat Feeds** | None Active |
---
## Network Profile
The IP operates within Microsoft's Azure cloud environment, part of BGP prefix 104.208.0.0/13. DNSSEC validation is valid. Operator score rated as "Minimal" (0.1304). One DNSBL listing detected across 8 total lists (insignificant impact). No open ports or active services identified on the endpoint.
---
## Threat Assessment
- Threat Indicators: None detected
- Campaign Matches: 0
- Known Attacker Status: False
- Tor Exit Node: False
- Spam Source: False
- Persistence: No persistent malicious activity observed
---
## Historical Observation (17 Total Signals)
Recent observations from 2026-06-15 show:
- Subnet classification: "mostly_clean"
- Inherited risk: 2 (low)
- Abuse density: 1 (minimal)
- No ownership changes detected
- No threat persistence days recorded
---
## Neighborhood Analysis
Subnet 104.211.76.0/24 demonstrates minimal abuse characteristics:
- Abuse Density: 1 (very low)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Risk Distribution: No high/medium risk neighbors
---
## Related Entities
Relationship graph contains 15 entries all associating with Microsoft (MSFT) network. No external organizational, hostname, or certificate relationships detected beyond Microsoft infrastructure.
---
## Recommended Actions
No firewall blocking or mitigation actions required. The IP represents legitimate cloud hosting infrastructure with low-risk characteristics. Standard cloud egress/ingress policies apply.
---
## Conclusion
IP 104.211.76.60 is a benign Microsoft Azure endpoint with no threat intelligence associations. SOC analysts may treat this as trusted infrastructure traffic. No correlation to active campaigns or malicious infrastructure networks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 15:17:37 UTC |
| Last Seen | 2026-06-28 19:34:25 UTC |
| Profile Built | 2026-06-29 07:39:20 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.