# IP INTELLIGENCE BRIEFING
Target: 20.187.112.227/32
Classification: Low Risk | Status: Routine Monitoring
## EXECUTIVE SUMMARY
IP address 20.187.112.227 is Microsoft Azure cloud infrastructure located in Hong Kong. The IP presents a low risk profile (Score: 25) with no active threat indicators. No malicious activity has been observed across 21 historical observations. The IP is properly classified as legitimate cloud hosting infrastructure with no open services detected.
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| Organization | Microsoft Corporation (MSFT) |
| ASN | 8075 |
| CIDR Block | 20.180.0.0/14 |
| Infrastructure Type | CloudCompute |
| Geolocation | Hong Kong, HK |
| RIR | ARIN |
| Provider Score | 0 |
| Risk Score | 25 |
## THREAT ASSESSMENT
Current Threat Indicators: None
Blacklist Status: 0 listings
Known Campaigns: None detected
Abuse Confidence Score: N/A
Tor Exit Node: No
Known Attacker: No
Spam Source: No
The IP has no associated threat feeds, known campaigns, or blacklist entries. The operator score is rated as "Minimal" (0.1304).
## NETWORK SERVICES
Open Ports: None detected
TLS Certificates: None
HTTP Services: None
Connection Type: Firewalled / No Services
The IP is operating as a cloud infrastructure endpoint with services actively blocked. No web or mail services are exposed.
## NEIGHBORHOOD ANALYSIS
Subnet: 20.187.112.227/24
Abuse Density: 0 (Clean)
Threat Siblings: 0
Classification: Clean
No neighboring IPs in the /24 subnet show abuse or threat activity. The subnet is classified as clean with no inherited risk.
## RELATIONSHIP GRAPH
Connected Entities: 7 relationships
Relationship Types: All "Same Network" (MSFT)
External Associations: None
The IP exists within Microsoft's corporate network with no external entity associations detected.
## HISTORICAL OBSERVATIONS
Total Observations: 21
Observation Period: Through 2026-08-05
Threat Persistence Days: 0
Ownership Changes: 0
Key Historical Signals:
- Cloud infrastructure classification maintained throughout
- No emergence of threat indicators
- Consistent Microsoft Azure network presence
- Geo validation challenges (ICMP blocked - unable to validate)
## RECOMMENDED ACTIONS
| System | Action |
|---|---|
| Firewall | No action required |
| SIEM | Monitor as legitimate cloud traffic |
| WAF | No rules required |
| Threat Intel | No blocking required |
Assessment: This IP represents legitimate Microsoft Azure cloud infrastructure with no security concerns. Routine traffic monitoring is appropriate. No blocking or mitigation actions are recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.180.0.0/14 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 01:11:35 UTC |
| Last Seen | 2026-08-12 16:33:53 UTC |
| Profile Built | 2026-08-12 16:48:49 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.