# IP INTELLIGENCE BRIEFING
IP Address: 104.43.48.106/32
Date: Current
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 104.43.48.106 is a Microsoft Azure cloud infrastructure endpoint located in Singapore. The asset presents a Low Risk profile with a risk score of 25/100. No active threat indicators were detected, though the IP shows one DNSBL listing among eight total lists. The address operates within a Microsoft-managed cloud environment with standard hosting services.
---
## NETWORK OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | Microsoft Corporation |
| **ASN** | AS8075 |
| **Netname** | MSFT |
| **CIDR Block** | 104.40.0.0/13 |
| **Registration** | ARIN |
| **Infrastructure Type** | CloudCompute |
| **Provider** | Microsoft Azure |
The IP resolves to Microsoft's public cloud infrastructure. No proxy, VPN, or Tor exit node characteristics were observed. The network is classified as hosting infrastructure with no detected open ports or active services.
---
## GEOLOCATION DATA
| Attribute | Value |
|---|---|
| **Country** | Singapore (SG) |
| **City** | Singapore |
| **Coordinates** | 1.35°N, 103.82°E |
| **Timezone** | Asia/Singapore |
| **GeoSource Consensus** | Yes |
| **Plausibility Score** | Valid |
---
## THREAT INDICATORS & REPUTATION
| Metric | Value |
|---|---|
| **Overall Risk Score** | 25 |
| **Abuse Confidence Score** | Not Available |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 1 of 8 lists |
| **Is Tor Exit** | No |
| **Is Known Attacker** | No |
| **Is Spam Source** | No |
| **Threat Feeds** | None |
| **Known Campaigns** | None |
No active threat indicators were detected. The single DNSBL listing represents minimal exposure.
---
## NEIGHBORHOOD ANALYSIS
| Metric | Value |
|---|---|
| **Subnet** | 104.43.48.0/24 |
| **Abuse Density** | 0% |
| **Classification** | Mostly Clean |
| **Total Siblings** | 2 |
| **Active Siblings** | 2 |
| **Threat Siblings** | 1 |
One neighboring IP (104.43.48.155) was observed with a risk score of 25 and authority score of 50. The subnet demonstrates minimal abuse activity.
---
## OBSERVATION HISTORY
- Total Observations: 20 signals
- Recent Activity: August 2026
- Key Observations:
- DNSSEC validation signals present
- Routing and reputation assessments completed
- Geolocation data consistently verified
- Ownership attribution stable (AS8075)
The IP maintains a stable profile with no significant reputation degradation or escalation over the observation window.
---
## RELATIONSHIP GRAPH
All detected relationships (10 total) are internal to the Microsoft network (MSFT). No external entity associations were identified, including:
- No associated hostnames
- No certificate relationships
- No organization cross-references
- No subnet anomalies
---
## SECURITY RECOMMENDATIONS
Risk Assessment: LOW RISK
Recommended Actions:
1. No immediate blocking required β Risk score of 25 indicates minimal threat
2. Monitor for DNSBL listing resolution β One DNSBL listing observed; verify if resolvable
3. Standard logging β Traffic from Microsoft Azure should be logged for forensic purposes
4. No firewall rules β No specific firewall rules generated based on current risk profile
Note: The IP operates within legitimate Microsoft Azure infrastructure. Blocking is not recommended without additional corroborating threat intelligence.
---
## CONCLUSION
IP 104.43.48.106 is a legitimate Microsoft Azure cloud endpoint with low-risk characteristics. The IP demonstrates standard cloud infrastructure behavior with no evidence of malicious activity. SOC teams may allow traffic with standard logging. No immediate mitigation actions are required.
Status: MONITOR
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 104.40.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-21 06:46:26 UTC |
| Last Seen | 2026-08-12 15:32:52 UTC |
| Profile Built | 2026-08-12 15:46:03 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.