# INTELLIGENCE BRIEFING: 158.158.44.35/32
## Executive Summary
IP address 158.158.44.35 is a Microsoft Azure cloud infrastructure endpoint classified as Low Risk. Analysis of the full intelligence profile, observation history, network relationships, and neighborhood data indicates this is a legitimate cloud computing resource with no active threat indicators.
## Technical Profile
Ownership and Registration
- ASN: 8075 (Microsoft Corporation)
- Organization: IRT-MICROSOFT-APNIC-SG
- Network Name: MICROSOFT-APNIC-AP
- CIDR Block: 158.158.0.0/16
- RIR: ARIN
Geolocation
- Country: ES (Spain)
- Region: MD
- City: Madrid
- Coordinates: 40.42, -3.7
- Accuracy: 150 km radius
Network Classification
- Infrastructure Type: CloudCompute
- Provider: Microsoft Azure
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- Is Cloud: Yes
- Is CDN: No
- Is Hosting: Yes
## Risk Assessment
Current Risk Score: 25 (Low Risk)
Risk Breakdown:
- Risk Score: 25/100
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Known Campaigns: None detected
Threat Indicators:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Pulsedive Risk: Not applicable
Network Neighborhood (158.158.44.0/24)
- Subnet Classification: Clean
- Abuse Density: 0%
- High-Risk Neighbors: 0
- Medium-Risk Neighbors: 0
- Low-Risk Neighbors: 0
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
## Signal Observation History
Recent Activity (16 observations tracked)
The IP has been under observation since June 2026 with consistent benign characteristics:
Key Observations:
- Abuse Density: 0 across all observations
- Classification: Clean (consistently)
- Inherited Risk: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
Observed Signal Types:
1. Subnet Classification - Clean classification maintained
2. Geolocation - Madrid, ES (multi-signal inference)
3. Threat Listings - 8 total DNSBL lists referenced, 1 high-severity listing
4. Operator Score - 0.1304 (Minimal)
5. Comprehensive Signal Profile - 13 total observations covering threat, routing, services, ownership, reputation, and geolocation dimensions
## Relationship Analysis
Network Relationships
- Count: 13 relationships identified
- Type: Same Network (all relationships)
- Target: MICROSOFT-APNIC-AP
- Consistency: All relationships confirm membership in Microsoft's network infrastructure
## Recommended Security Actions
Based on the IP's low-risk profile and Microsoft Azure cloud infrastructure classification, the following actions are recommended:
Recommended Actions: None required
Rationale: This IP exhibits characteristics of legitimate Microsoft cloud infrastructure with no active threat indicators. No blocking or filtering is necessary unless this IP appears in your specific threat context or is associated with a known malicious activity pattern.
Monitoring Considerations: Continue passive monitoring as part of normal network operations. The IP's cloud infrastructure nature means it may route through multiple Microsoft data centers and should be treated as a legitimate service provider endpoint.
---
*Report generated: IPDebrief Intelligence Analysis System*
*Classification: Network Intelligence - Defensive Security*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-MICROSOFT-APNIC-SG |
| ASN | AS8075 |
| Network Name | MICROSOFT-APNIC-AP |
| CIDR Block | 158.158.0.0/16 |
| RIR | ARIN |
| Country | SG |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 00:40:30 UTC |
| Last Seen | 2026-06-29 00:50:42 UTC |
| Profile Built | 2026-06-29 06:54:09 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.