# IP Intelligence Briefing: 158.158.41.78/32
Classification: MODERATE RISK
Date: Intelligence generated from current observation window
---
## Executive Summary
IP 158.158.41.78 is a Microsoft Azure cloud compute address registered to Singapore (SG) with a moderate risk score of 65/100. The IP exhibits no direct threat indicators or persistent malicious activity. Neighborhood analysis indicates low abuse density within the /24 subnet.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 158.158.41.78/32 |
| **Risk Score** | 65 (Moderate) |
| **Provider** | Microsoft Azure |
| **Infrastructure Type** | CloudCompute |
| **Country** | Singapore (SG) |
| **ASN** | 8075 |
| **BGP Prefix** | 158.158.0.0/16 |
| **Open Ports** | None detected |
| **DNS Resolution** | No PTR records, no forward resolution |
---
## Threat Assessment
Threat Indicators:
- No known attacker patterns detected
- Not listed as Tor exit node or VPN/proxy
- Spam source: Negative
- Blacklist count: 0
- DNSBL listings: 3/8 total lists
Behavioral Analysis:
- Not an active attacker
- No honeypot hits recorded
- No enumeration strikes detected
- No WAF violations observed
- Not persistently malicious
---
## Control Plane Analysis
- Origin ASN: 8075 (Microsoft Corporation)
- Route Stability: False (dynamic cloud routing)
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not assessed
- IRR Consistency: Not assessed
---
## Neighborhood Intelligence
Subnet: 158.158.41.0/24
Abuse Density: 0
Neighbor Count: 2
| Neighbor IP | Risk Score | Authority Score | Classification |
|---|---|---|---|
| 158.158.41.185 | 25 | 50 | Low Risk |
| 158.158.41.212 | 25 | 50 | Low Risk |
The /24 subnet shows no high or medium risk neighbors. Overall neighborhood risk is low.
---
## Observation History
Total Observations: 11
Time Range: Current observation window
Recent signal types observed:
- Traceroute analysis (18 hops)
- Port scanning attempts (no open services)
- Geolocation validation (SG consensus)
- Operator scoring (Minimal classification)
---
## Related Entities
No associated relationships detected (subnets, hostnames, organizations, or certificates).
---
## Recommended Actions
Based on the moderate risk profile and cloud infrastructure classification:
1. Allow with monitoring - Not flagged as malicious, but maintain baseline monitoring
2. No firewall blocking required - No threat indicators present
3. Standard cloud traffic handling - Apply Microsoft Azure egress rules if applicable
4. DNSBL review - Investigate 3 DNSBL listings if source of connection anomalies
---
## SOC Analyst Notes
This IP represents legitimate Microsoft Azure infrastructure. The moderate risk score (65) correlates with cloud hosting classification rather than active malicious behavior. No immediate blocking recommended. Monitor for changes in threat indicators or neighborhood abuse density.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-MICROSOFT-APNIC-SG |
| ASN | AS8075 |
| Network Name | MICROSOFT-APNIC-AP |
| CIDR Block | 158.158.0.0/16 |
| RIR | ARIN |
| Country | SG |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 1 |
| geolocation | 42% | 2 | 3 |
| Overall | 28% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 20:05:09 UTC |
| Last Seen | 2026-08-12 17:55:10 UTC |
| Profile Built | 2026-08-12 18:08:01 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.