## IP Intelligence Briefing: 20.170.17.213/32
Classification: Moderate Risk / Microsoft Azure Infrastructure
Risk Score: 65/100
Analysis Date: 2026-08-06
Ownership and Infrastructure
The IP 20.170.17.213 belongs to Microsoft Corporation (ASN 8075), registered under MSFT within the 20.160.0.0/12 CIDR block. The address is allocated to Microsoft Azure cloud infrastructure (CloudCompute) and is geolocated to Frankfurt am Main, Germany (DE). The IP is classified as hosting infrastructure with no residential, proxy, or CDN characteristics.
Network Context
The /24 subnet (20.170.17.0/24) shows a clean classification with zero abuse density and no active siblings detected in the neighborhood. Seven relationship links were identified, all pointing to Microsoft network infrastructure (MSFT), indicating the IP operates within Microsoft's broader network topology.
Threat Indicators
- DNSBL Status: Listed on 3 out of 8 total DNSBL feeds
- Threat Classifications: No known attacker, spam source, or Tor exit node indicators
- Campaign Association: No known campaigns or correlated IPs
- Active Threats: None observed; no open ports or services detected during scanning
Observational History
Eighteen observations recorded, with the most recent signal from 2026-08-06. The IP maintains stability with no ownership changes or persistent malicious behavior. Operator score of 0.1304 indicates minimal reputation risk.
Recommended Actions
Priority: Monitor (High severity recommendation based on elevated risk score)
1. Immediate: Increase logging verbosity for traffic from this IP address
2. Review: Examine recent connection activity and payloads for anomalous patterns
3. Firewall Mitigation: If blocking is required, apply the following rules:
- `iptables -A INPUT -s 20.170.17.213 -j DROP`
- `nft add rule inet filter input ip saddr 20.170.17.213 drop`
Analyst Notes
This IP represents legitimate Microsoft Azure infrastructure but registers a moderate risk score (65/100) with multiple DNSBL listings. While the infrastructure type and ownership are verified as Microsoft, the reputation flags suggest potential abuse or reputation degradation. Recommend enhanced monitoring rather than immediate blocking unless specific malicious activity is observed in logs.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.160.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-03 23:38:50 UTC |
| Last Seen | 2026-08-13 05:40:53 UTC |
| Profile Built | 2026-08-13 05:52:39 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.