# IP Intelligence Briefing: 20.100.193.33/32
Date: 2026-08-13
IP Address: 20.100.193.33
Risk Score: 65/100 (Moderate Risk)
Classification: Microsoft Azure Cloud Infrastructure
## Ownership and Infrastructure
The IP belongs to Microsoft Corporation (ASN 8075, MSFT) within the 20.33.0.0/16 CIDR block. The address operates on Microsoft Azure infrastructure with cloud computing classification. No services are actively exposed on this endpointβconnections return "Firewalled / No Services" status with no open ports detected.
## Geolocation Signals
Geolocation data presents conflicting signals. Current profile indicates Oslo, Norway (NO), while historical observations from 2026-08-13 show Boston, US (US-MA) with 70% confidence, resolving to be21.owr02.bos01.ntwk.msn.net. This discrepancy warrants attention but is consistent with Microsoft's multi-region Azure deployment patterns.
## Threat Indicators
- DNSBL Listings: 3 out of 8 total threat feeds list this IP
- Not classified as: Tor exit node, known attacker, or spam source
- Campaign correlation: No matching campaigns detected
- Threat persistence: Single threat observation, not persistently malicious
## Neighborhood Analysis
The /24 subnet (20.100.193.0/24) shows 0 abuse density with no neighboring IPs flagged as threats. This suggests the elevated risk score may be IP-specific rather than subnet-wide.
## Control Plane Data
Route stability is flagged as false. DNSSEC validation is active. Operator score: 0.1304 (Minimal).
## Historical Observations
Twenty-four observations recorded. Recent activity (2026-08-13) includes:
- DNSBL listings with high severity categorization
- Traceroute attempts reaching target failed
- No new threat indicators observed in most recent signals
## Recommended Actions
1. Increase logging verbosity for traffic from this IP due to elevated risk score
2. Review recent activity patterns to determine if traffic is authorized
3. Consider blocking if traffic is unauthorizedβfirewall rules available for iptables, nftables, nginx, pfSense, Cloudflare WAF, and AWS WAF
## Assessment
This IP exhibits moderate risk characteristics within a Microsoft Azure environment. The elevated risk score is driven by DNSBL listings rather than confirmed malicious activity. No open services detected. The geolocation inconsistency and DNSBL presence warrant monitoring but do not confirm active threat activity.
Status: Monitor with increased scrutiny; block if traffic is not expected from Microsoft Azure infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.33.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 18% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-03 23:38:50 UTC |
| Last Seen | 2026-08-13 05:39:43 UTC |
| Profile Built | 2026-08-13 05:52:39 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.