IP Intelligence Briefing: 20.123.146.92
Date: 2026-06-18
---
**1. Core Profile**
- Reputation: Moderate Risk (Risk Score: 65)
- Ownership: Microsoft Corporation (ASN 8075, Microsoft Azure)
- Geolocation: Amsterdam, Netherlands (US-registered, 2500km accuracy radius)
- Network Role: CloudCompute (Microsoft Azure) β Firewalled / No Services
- Threat Indicators: No malicious activity detected (no IOC, blacklist, or campaign ties).
---
**2. Observation History**
- Signal Trends:
- Minimal risk score (0.2174) over 30 days.
- DNSSEC and CAA validation active, but DNS resolution errors observed.
- No persistent malicious behavior or threat persistence.
- Key Findings:
- DNS queries timed out, suggesting potential misconfiguration or network instability.
- No correlation with known malicious campaigns or threat feeds.
---
**3. Relationships**
- Network Associations:
- Directly linked to Microsoft Azure infrastructure (MSFT).
- No connections to known malicious organizations, domains, or certificates.
- DNS Associations:
- Failed DNS resolution attempts (timed out).
---
**4. Neighborhood Analysis**
- Subnet: 20.123.146.92/24
- Neighbor Risk:
- 3 active siblings with risk scores of 65 (same as the IP).
- Subnet abuse density: 0 (mostly clean).
- Notable:
- Neighbors share similar risk profiles but no direct malicious ties.
---
**5. Recommendations**
- Monitor DNS Configuration: Investigate recurring DNS resolution failures.
- Network Segmentation: Ensure isolation between Azure infrastructure and internal networks.
- Neighbor Analysis: Continuously monitor siblings for unexpected behavior.
- Threat Feeds: Cross-reference with IOC databases to confirm no missed indicators.
---
Conclusion: This IP is part of Microsoft Azureβs infrastructure with no direct malicious activity. However, DNS instability and peers with moderate risk scores warrant further scrutiny.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:07 UTC |
| Last Seen | 2026-06-27 03:05:16 UTC |
| Profile Built | 2026-06-27 21:10:48 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.