Intelligence Briefing: 128.85.113.134/32
Observations recorded between 2026-09-03 and 2026-09-11 categorized this address as Low Risk (Score: 25). Ownership attribution linked the IP to Microsoft Corporation (ASN 8075) within the ARIN registry. Network role classification identified the endpoint as a Microsoft Azure CloudCompute web server with hosting infrastructure.
Passive scanning detected open TCP ports 80 and 443. Server fingerprinting returned Microsoft-IIS/10.0 with ASP.NET headers. The associated TLS certificate issued by Microsoft Update Secure Server CA covered the fe2.update.microsoft.com subject name. DNS configuration included SPF and DMARC records.
Threat indicators showed no association with known campaigns or active attacker status. The address appeared on one DNS blacklist of eight evaluated lists. Neighborhood analysis of subnet 128.85.113.0/24 classified the environment as mostly clean, though abuse density measured 0.6667 with two threat siblings active.
Geolocation validation revealed a contradiction between claimed location (Quincy, WA, US) and RTT physics measurements. Minimum possible RTT for the distance was 157.7ms, while observed RTT was 88ms. Recommendation: Monitor the endpoint for potential configuration changes or anomaly escalation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 128.85.0.0/17 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Microsoft-IIS/10.0 |
| HTTP Title | β |
π TLS Certificate
| SANs | fe2.update.microsoft.com |
| Valid From | 2026-01-22T20:47:39+00:00 |
| Valid Until | 2027-01-22T20:47:39+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 330000028D431F2E04AD2C43C900000000028D |
| Thumbprint | FEAF9A057ECBDE927A412A3049696E740E6A8E1D |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 38% | 2 | 5 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 4 |
| geolocation | 27% | 2 | 4 |
| Overall | 27% | 10 | 21 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-03 13:22:32 UTC |
| Last Seen | 2026-09-20 04:48:10 UTC |
| Profile Built | 2026-09-23 02:37:53 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 34 |
Full dossier details are available via our API.