# IP Intelligence Briefing: 158.158.76.249/32
## Executive Summary
IP 158.158.76.249 is registered to Microsoft Azure (AS8075) and classified as a cloud computing endpoint with moderate risk scoring (50). The IP shows no active services, no open ports, and minimal threat indicators. While the address is hosted on legitimate Microsoft infrastructure, it has generated 2 DNSBL listings and shows neighborhood-level abuse density in its /24 subnet.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| Organization | IRT-MICROSOFT-APNIC-SG (MICROSOFT-APNIC-AP) |
| ASN | AS8075 |
| Network | 158.158.0.0/16 |
| Infrastructure Type | CloudCompute (Microsoft Azure) |
| Geolocation | Madrid, ES (reported); Singapore coordinates in probe data |
| RIR | ARIN |
## Threat Indicators
- Risk Score: 50 (Moderate)
- Blacklist Status: 2 DNSBL listings across 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Open Ports: None detected
- Active Services: None
## Neighborhood Analysis
The IP resides in subnet 158.158.76.0/24 with the following characteristics:
- Abuse Density: 0.5 (moderate)
- Subnet Classification: mostly_clean
- Total Siblings: 4 active IPs
- Threat Siblings: 2
- Neighbor Risk Scores: 0, 25, 25 (low-risk distribution)
## Historical Observations
The IP has been observed 22 times in the monitoring system. Recent signals indicate:
- Subnet abuse density consistently at 0.5
- Traceroute analysis revealed 30 hops with incomplete target reach
- Geo validation noted ICMP blocks preventing full geographic confirmation
- AlienVault OTX data places the IP in Singapore (SG)
## Relationship Graph
The IP maintains multiple relationships to the MICROSOFT-APNIC-AP network block, consistent with Microsoft Azure cloud infrastructure patterns.
## Recommended Actions
Based on the risk profile, the following mitigations are recommended:
| Platform | Action |
|---|---|
| iptables | `iptables -A INPUT -s 158.158.76.249 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 158.158.76.249 drop` |
| nginx | `deny 158.158.76.249;` |
| pfSense | Add 158.158.76.249/32 to block list |
| Cloudflare WAF | Configure rule: `ip.src eq 158.158.76.249` โ Block |
| AWS WAF | Add address: 158.158.76.249/32 |
## Analyst Notes
The moderate risk score (50) primarily stems from DNSBL listings rather than active threat indicators. The IP operates on Microsoft Azure infrastructure with no exposed services. Given the neighborhood's low-to-moderate abuse density, this appears to be a legitimate cloud endpoint with historical or incidental reputation issues. Blocking is recommended as a precautionary measure, but the IP does not exhibit characteristics of active malicious infrastructure.
---
*Generated: 2026-08-13 | Source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-MICROSOFT-APNIC-SG |
| ASN | AS8075 |
| Network Name | MICROSOFT-APNIC-AP |
| CIDR Block | 158.158.0.0/16 |
| RIR | ARIN |
| Country | SG |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-01 16:33:10 UTC |
| Last Seen | 2026-08-13 02:42:57 UTC |
| Profile Built | 2026-08-13 02:55:41 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.