IP Intelligence Briefing: 20.185.9.149
Date: 2026-06-18
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Microsoft Corporation (ASN 8075)
- Geolocation: Virginia, US (37.37°N, -79.46°E)
- Network Role: Microsoft Azure CloudCompute
- Threat Indicators: No malicious activity detected (empty threat feeds, no known campaigns).
- DNS/Services: No open ports, TLS certs, or DNS records resolved.
---
**2. Observation History**
- Recent Activity (June 18, 2026):
- Detected as a proxy/VPN (score 66) with Microsoft Corporation as the provider.
- Confidence: 85% (proxycheck.io).
- Earlier Activity (June 14, 2026):
- Geolocation inferred as Virginia, US (confidence 56%).
- Linked to Microsoftβs network infrastructure (AlienVault OTX).
- Trend: Mixed signals, but no persistent malicious behavior.
---
**3. Relationships**
- Network Associations:
- Directly tied to Microsoft Azure (MSFT) via ASN 8075.
- DNS Associations:
- Multiple failed DNS queries to private IP `192.168.2.108` (likely misconfigured or internal).
- No External Hostnames: No public DNS records or domain associations.
---
**4. Neighborhood Analysis**
- Subnet: 20.185.9.149/24
- Neighbor Count: 0 (no public IPs in subnet found).
- Abuse Density: 0 (no risky neighbors).
---
**5. Control Plane & Infrastructure**
- BGP Prefix: 20.184.0.0/13 (Microsoft-owned).
- Routing: Stable (no recent route changes).
- DNSSEC: Validated.
- CAA Records: Present.
---
**6. Recommendations**
- Monitor: Track for unexpected DNS resolution or port activity, as the IP is associated with Microsoftβs infrastructure.
- Verify: Investigate DNS timeout errors (`192.168.2.108`) to ensure no misconfigured internal services.
- Context: Low-risk, but proxy detection suggests potential misuse. Confirm if this IP is part of authorized Azure resources.
---
Note: No immediate threat detected, but ongoing monitoring is advised due to mixed signals and proxy associations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:07 UTC |
| Last Seen | 2026-06-27 03:12:00 UTC |
| Profile Built | 2026-06-27 21:18:49 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 30 |
Full dossier details are available via our API.