IPDebrief

104.43.48.106

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

IP Address: 104.43.48.106/32

Date: Current

Analyst: IPDebrief Intelligence Team

---

## EXECUTIVE SUMMARY

IP 104.43.48.106 is a Microsoft Azure cloud infrastructure endpoint located in Singapore. The asset presents a Low Risk profile with a risk score of 25/100. No active threat indicators were detected, though the IP shows one DNSBL listing among eight total lists. The address operates within a Microsoft-managed cloud environment with standard hosting services.

---

## NETWORK OWNERSHIP & INFRASTRUCTURE

AttributeValue
**Organization**Microsoft Corporation
**ASN**AS8075
**Netname**MSFT
**CIDR Block**104.40.0.0/13
**Registration**ARIN
**Infrastructure Type**CloudCompute
**Provider**Microsoft Azure

The IP resolves to Microsoft's public cloud infrastructure. No proxy, VPN, or Tor exit node characteristics were observed. The network is classified as hosting infrastructure with no detected open ports or active services.

---

## GEOLOCATION DATA

AttributeValue
**Country**Singapore (SG)
**City**Singapore
**Coordinates**1.35°N, 103.82°E
**Timezone**Asia/Singapore
**GeoSource Consensus**Yes
**Plausibility Score**Valid

---

## THREAT INDICATORS & REPUTATION

MetricValue
**Overall Risk Score**25
**Abuse Confidence Score**Not Available
**Blacklist Count**0
**DNSBL Listed**1 of 8 lists
**Is Tor Exit**No
**Is Known Attacker**No
**Is Spam Source**No
**Threat Feeds**None
**Known Campaigns**None

No active threat indicators were detected. The single DNSBL listing represents minimal exposure.

---

## NEIGHBORHOOD ANALYSIS

MetricValue
**Subnet**104.43.48.0/24
**Abuse Density**0%
**Classification**Mostly Clean
**Total Siblings**2
**Active Siblings**2
**Threat Siblings**1

One neighboring IP (104.43.48.155) was observed with a risk score of 25 and authority score of 50. The subnet demonstrates minimal abuse activity.

---

## OBSERVATION HISTORY

- DNSSEC validation signals present

- Routing and reputation assessments completed

- Geolocation data consistently verified

- Ownership attribution stable (AS8075)

The IP maintains a stable profile with no significant reputation degradation or escalation over the observation window.

---

## RELATIONSHIP GRAPH

All detected relationships (10 total) are internal to the Microsoft network (MSFT). No external entity associations were identified, including:

---

## SECURITY RECOMMENDATIONS

Risk Assessment: LOW RISK

Recommended Actions:

1. No immediate blocking required – Risk score of 25 indicates minimal threat

2. Monitor for DNSBL listing resolution – One DNSBL listing observed; verify if resolvable

3. Standard logging – Traffic from Microsoft Azure should be logged for forensic purposes

4. No firewall rules – No specific firewall rules generated based on current risk profile

Note: The IP operates within legitimate Microsoft Azure infrastructure. Blocking is not recommended without additional corroborating threat intelligence.

---

## CONCLUSION

IP 104.43.48.106 is a legitimate Microsoft Azure cloud endpoint with low-risk characteristics. The IP demonstrates standard cloud infrastructure behavior with no evidence of malicious activity. SOC teams may allow traffic with standard logging. No immediate mitigation actions are required.

Status: MONITOR

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
RegionSG
CitySingapore
TimezoneAsia/Singapore
Latitude1.35
Longitude103.82

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network NameMSFT
CIDR Block104.40.0.0/13
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
Cloud

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
40%
25
routing
13%
11
services
19%
22
ownership
27%
23
reputation
26%
13
geolocation
30%
23
Overall26%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-21 06:46:26 UTC
Last Seen2026-08-12 15:32:52 UTC
Profile Built2026-08-12 15:46:03 UTC
Data FreshnessLive
Signal Types19
Total Observations22
πŸ” 19 signal types Β· 22 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.