# IP INTELLIGENCE BRIEFING: 158.158.43.249/32
Classification: LOW RISK - Cloud Infrastructure
Date Generated: 2026-06-17
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 158.158.43.249 is identified as Microsoft Azure cloud infrastructure with a low-risk profile (score: 25). The address represents legitimate cloud compute infrastructure hosted in Madrid, Spain, with no active threat indicators, blacklist entries, or known malicious campaigns. Recommended actions: monitor but no immediate blocking required.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **ASN** | 8075 (MICROSOFT) |
| **Organization** | IRT-MICROSOFT-APNIC-SG |
| **Network** | MICROSOFT-APNIC-AP (158.158.0.0/16) |
| **Geolocation** | Madrid, Spain (ES) |
| **Network Role** | Microsoft Azure Cloud Compute |
| **Classification** | Cloud Hosting, Firewalled/No Services |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
---
## THREAT ASSESSMENT
Active Indicators
- Blacklist Status: Not listed (0/0 lists)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Active Threats: None detected
- Known Campaigns: None correlated
Service Exposure
- Open Ports: None detected
- TLS Certificate: None
- HTTP Services: None
- DNS Records: No forward resolution
- Status: Firewalled/no services exposed
---
## OBSERVATION HISTORY
Total Observations: 23 signals tracked
Temporal Analysis
- Most Recent Activity: 2026-06-17 14:48 UTC
- Geolocation Consistency: Madrid, ES (consistent across observations)
- Operator Score: 0.3478 (Basic - stable)
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0 (stable)
Signal Evolution
- June 2026: Consistent cloud infrastructure signals
- No escalation in threat indicators
- No routing anomalies detected
- Route stability: Confirmed
---
## NETWORK RELATIONSHIPS
Direct Relationships: 25 identified (all same-network links to MICROSOFT-APNIC-AP)
Control Plane:
- BGP Prefix: 158.158.0.0/16
- AS Path: 49788 โ 8075
- RPKI State: Stable
- Route Changes (30d): 0
- DNSSEC Valid: Yes
---
## NEIGHBORHOOD ANALYSIS
Subnet: 158.158.43.0/24
| Metric | Value |
|---|---|
| Abuse Density | 0 (Mostly Clean) |
| Total Siblings | 2 |
| Active Siblings | 2 |
| Threat Siblings | 2 |
| Inherited Risk | 5 |
Neighbor Profile:
- 158.158.43.239: Risk Score 25 (Same risk level)
---
## SECURITY RECOMMENDATIONS
Current Status
Risk Score: 25 (Low)
Action Required: None
Firewall/Policy Guidance
- Immediate Blocking: NOT RECOMMENDED
- Rate Limiting: Consider standard cloud provider thresholds
- Monitoring: Continue standard traffic monitoring
- Threat Hunting: No specific IOCs required
Rationale
This IP represents legitimate Microsoft Azure infrastructure. No active threat indicators, blacklist entries, or malicious campaigns detected. The subnet demonstrates clean abuse density with consistent cloud infrastructure patterns.
---
## INTELLIGENCE SIGNATURES
Validated Indicators:
- ASN 8075 (Microsoft Corporation)
- 158.158.0.0/16 prefix allocation
- Madrid, ES geolocation consensus
- Azure cloud compute classification
Notable Absences:
- No open ports or services
- No TLS certificates
- No DNS records
- No blacklist entries
- No threat feed correlations
---
END BRIEFING
*Intel generated from IPDebrief platform data. Validated through multi-signal analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-MICROSOFT-APNIC-SG |
| ASN | AS8075 |
| Network Name | MICROSOFT-APNIC-AP |
| CIDR Block | 158.158.0.0/16 |
| RIR | ARIN |
| Country | SG |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 6 |
| routing | 24% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 26% | 11 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:49 UTC |
| Last Seen | 2026-06-27 00:50:25 UTC |
| Profile Built | 2026-06-27 21:02:36 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 33 |
Full dossier details are available via our API.