# IP Intelligence Briefing: 20.192.26.228/32
## Executive Summary
IP address 20.192.26.228 is identified as Microsoft Azure cloud infrastructure located in Pune, Maharashtra, India. The IP carries a moderate risk score of 50, primarily attributable to DNSBL listings rather than active malicious behavior. No threat indicators, campaigns, or known attacker associations were detected. This IP represents legitimate cloud compute infrastructure operating within Microsoft's Azure network (AS8075).
---
## Ownership & Network Classification
- Organization: Microsoft Corporation (MSFT)
- ASN: 8075
- CIDR Block: 20.192.0.0/10
- Network Role: Microsoft Azure Cloud Compute, Multi-Service Host
- Geolocation: Pune, Maharashtra, India (IN)
- Infrastructure Type: CloudCompute (confirmed cloud infrastructure)
- DNSSEC: Valid
## Threat Assessment
- Overall Risk Score: 50 (Moderate Risk)
- Abuse Confidence Score: Not applicable (cloud infrastructure)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 (active threat feeds)
- Known Campaigns: None detected
## Service Exposure
- Open Ports: 80/TCP (HTTP), 22/TCP (SSH)
- Web Server: nginx/1.24.0 (Ubuntu)
- HTTP Title: None detected
- TLS Certificate: None exposed
## Neighborhood Analysis
Subnet 20.192.26.228/24 shows:
- Abuse Density: 0 (clean classification)
- Threat Siblings: 0
- Active Siblings: 0
- Risk Distribution: No high or medium risk neighbors detected
## Observation History
Recent signal observations indicate:
- Subnet Classification: Clean with 0 abuse density
- DNSBL Status: Listed on 2 of 8 threat lists (max severity: high)
- Cloud Infrastructure: Confirmed Microsoft Azure
- Operator Score: Minimal (0.1304)
- Threat Persistence: No persistent malicious activity observed
## Network Relationships
All 12 detected relationships point to Microsoft (MSFT) network associations, confirming the IP's placement within Microsoft's Azure infrastructure network. No external threat correlations or campaign links were identified.
---
## Recommended Security Actions
Based on the moderate risk score of 50, the following firewall rules are recommended. Note: These are probabilistic recommendations and should be evaluated against operational context. Microsoft Azure cloud infrastructure may require whitelisting for legitimate business operations.
Firewall Blocking Rules (if blocking is required):
iptables:
```bash
iptables -A INPUT -s 20.192.26.228 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 20.192.26.228 drop
```
nginx:
```nginx
deny 20.192.26.228;
```
pfSense:
```
20.192.26.228/32
```
Cloudflare WAF:
```json
{
"description": "Block 20.192.26.228 โ IPDebrief risk score 50",
"action": "block",
"filter": {
"expression": "ip.src eq 20.192.26.228"
}
}
```
AWS WAF:
```json
{
"Addresses": ["20.192.26.228/32"],
"Description": "IPDebrief risk 50"
}
```
---
## Intelligence Assessment
This IP address represents legitimate Microsoft Azure cloud infrastructure rather than malicious activity. The moderate risk score (50) appears to be a function of DNSBL listings rather than confirmed malicious behavior. The subnet shows no abuse density and no threat siblings.
Recommended Action: Evaluate against operational requirements. If this IP is not expected to generate traffic to your infrastructure, blocking may be applied with low operational risk. If Microsoft Azure services are legitimately used, consider whitelisting or monitoring rather than blocking.
Confidence Level: High - confirmed cloud infrastructure with no active threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | nginx/1.24.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 31% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 24% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 06:47:10 UTC |
| Last Seen | 2026-08-12 15:36:04 UTC |
| Profile Built | 2026-08-12 15:46:02 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.