## IP Intelligence Briefing: 20.115.94.226
Classification: Microsoft Azure Cloud Infrastructure
Risk Rating: Low Risk (Score: 25/100)
Date: 2026-06-21
---
Executive Summary
IP 20.115.94.226 is identified as Microsoft Corporation infrastructure deployed within Microsoft Azure cloud services. The IP demonstrates low-risk characteristics with no active threat indicators, zero blacklist listings, and no observed malicious activity. The address operates as a cloud computing endpoint with services in firewalled/no-service state.
---
Technical Profile
Ownership & Registration:
- ASN: 8075 (Microsoft Corporation)
- Organization: MSFT
- CIDR Block: 20.33.0.0/16
- RIR: ARIN
Geolocation:
- Country: United States (US)
- Region: Virginia (VA)
- Coordinates: 37.37°N, -79.46°W
- Timezone: America/New_York
Network Role:
- Provider: Microsoft Azure
- Infrastructure Type: CloudCompute
- Classification: Cloud Infrastructure
- Service State: Firewalled / No Services
---
Threat Assessment
Current Risk Indicators:
- Risk Score: 25/100 (Low Risk)
- Blacklist Count: 0
- Abuse Confidence: Not elevated
- Known Campaigns: None
- Threat Feeds: Empty
Malicious Activity Detection:
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Is Proxy: No
- Is VPN: No
---
Neighborhood Analysis
Subnet: 20.115.94.226/24
Abuse Density: 0.00 (Clean)
Classification: Mostly Clean
Sibling IP Risk Distribution:
- High Risk: 0 IPs
- Medium Risk: 1 IP (20.115.94.237, Risk: 50)
- Low Risk: 1 IP (20.115.94.228, Risk: 25)
The /24 subnet demonstrates minimal abuse activity with only one neighbor showing medium-risk classification.
---
Relationship Graph
Connected Entities: 16 relationships identified
- Type: Same Network (MSFT/Microsoft)
- All relationships point to Microsoft corporate network infrastructure
The IP maintains network-level associations exclusively with Microsoft's enterprise infrastructure, confirming legitimate cloud hosting origin.
---
Observation History
Total Observations: 22 signals tracked
Data Freshness: Recent observations from 2026-06-21
Key Historical Signals:
- BGP routing confirmed through Microsoft ASN 8075
- Subnet abuse density consistently classified as "mostly_clean"
- Cloud infrastructure classification stable
- Geolocation inference: Virginia, US (56% confidence)
- No persistent malicious behavior detected
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence: 0 days
- Persistently Malicious: No
---
Network Services
Open Ports: None detected
TLS Certificates: None
HTTP Services: None
DNS Records: No PTR hostnames, forward resolution not confirmed
Email Auth: No SPF/DMARC records detected
The IP presents as a firewalled endpoint with no publicly accessible services, consistent with cloud infrastructure security posture.
---
Recommended Actions
SOC Analyst Guidance:
- No blocking recommended; traffic is legitimate Microsoft Azure infrastructure
- Monitor for any unexpected service exposure on this IP
- Neighbor 20.115.94.237 (Risk: 50) warrants periodic review for potential abuse correlation
- No firewall rules required for defensive posture
Conclusion: This IP represents standard Microsoft Azure cloud infrastructure with no immediate threat indicators. No action required beyond routine monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.33.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 34% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 23% | 1 | 2 |
| geolocation | 26% | 2 | 2 |
| Overall | 27% | 11 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-02 12:03:51 UTC |
| Last Seen | 2026-06-29 10:51:50 UTC |
| Profile Built | 2026-06-29 16:53:43 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.