# IP Intelligence Briefing: 20.161.70.163/32
Classification: LOW RISK β Legitimate Microsoft Azure Infrastructure
Date: June 16, 2026
---
## Executive Summary
IP address 20.161.70.163 is identified as Microsoft Azure cloud infrastructure with a low risk score of 25. The asset demonstrates clean neighborhood metrics, no malicious indicators, and stable ownership under Microsoft Corporation (ASN 8075). No security actions or firewall blocks are recommended for this IP.
---
## Ownership & Network Classification
| Field | Value |
|---|---|
| Organization | Microsoft Corporation |
| ASN | 8075 (MSFT) |
| CIDR Block | 20.160.0.0/12 |
| Network Role | Microsoft Azure CloudCompute |
| Infrastructure Type | CloudCompute |
| Hosting Status | Yes |
Control Plane Data:
- BGP Prefix: 20.160.0.0/12
- Route Stability: Unstable
- DNSSEC Valid: True
- Operator Score: 0.1304 (Minimal)
- RIR: ARIN
---
## Geolocation
| Field | Value |
|---|---|
| Country | United States (US) |
| Region | Virginia |
| City | Virginia |
| Coordinates | 36.67°N, -78.93°W |
| Timezone | America/New_York |
| Accuracy Radius | 150 km |
---
## Threat Intelligence
Risk Assessment:
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence Score: N/A
- Blacklist Count: 0
- Known Campaigns: None
Threat Indicators:
- Is Tor Exit Node: False
- Is Known Attacker: False
- Is Spam Source: False
- DNSBL Listed: 1 of 8 total lists
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: None observed
---
## Services & Network Behavior
Open Ports: None detected
TLS Certificates: Not present
HTTP Titles: Not present
Server Banners: None observed
Open Ports Scanned: Multiple ports scanned (details omitted)
DNS Analysis:
- PTR Hostnames: None
- Forward Resolution: False
- Hosted Domains: 0
- Email Auth Records: SPF: No, DMARC: No
Network Behavior:
- Hop Count: 19
- First Hop RTT: 0.2ms
- Last Hop RTT: 34ms
- Timed Out Hops: 6
- Transit Networks: Comcast
---
## Neighborhood Analysis
Subnet: 20.161.70.0/24
Abuse Density: 0 (Clean)
Classification: Clean
Total Siblings: 2
Active Siblings: 0
Threat Siblings: 0
Neighbor IP Analysis:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 20.161.70.184 | 25 | 50 |
---
## Observation History
Total Observations: 17
Recent Activity (June 16, 2026):
- 17:37:54 β Banner analysis (confidence: 0.30)
- 17:32:02 β Port scanning activity detected
- 16:57:11 β Geolocation inference: Virginia, US
- 16:48:36 β Ownership stability confirmed
- 16:47:40 β Organization confirmed: Microsoft Corporation
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: False
---
## Relationships
All 5 relationship links point to Microsoft network infrastructure (MSFT). No external or suspicious entity connections detected.
---
## Recommended Actions
Security Recommendations: None required
Firewall Rules: Not applicable
Risk Score: 25
---
## Analyst Notes
This IP represents legitimate Microsoft Azure cloud infrastructure. The asset shows no evidence of malicious activity, with clean neighborhood metrics and no threat indicators. The low risk score (25) and absence of blacklist entries support continued trust. No firewall rules or blocking actions are recommended.
Final Classification: LEGITIMATE β Microsoft Azure Infrastructure
Recommendation: No action required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.160.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 24% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-09 20:27:14 UTC |
| Last Seen | 2026-06-21 16:42:43 UTC |
| Profile Built | 2026-06-21 16:45:03 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.