IP INTELLIGENCE BRIEFING: 20.193.226.228/32
Executive Summary
The IP address 20.193.226.228 was identified as a Microsoft Azure cloud infrastructure endpoint with a moderate risk profile (score: 65). The asset operates within Microsoft's 20.192.0.0/10 CIDR block and shows no active threat indicators or malicious behavior.
Asset Profile
- Organization: Microsoft Corporation (ASN 8075, MSFT)
- Network Classification: CloudCompute / Microsoft Azure
- Geolocation: Pune, Maharashtra, India (IN)
- Infrastructure Status: Firewalled with no open services detected
Risk Assessment
The IP registered a risk score of 65. Analysis revealed the following risk factors:
- Listed on 3 of 8 DNSBLs
- Route stability issues detected in control plane data
- Low operator score (0.1304) indicating minimal operational control
Threat Intelligence
- Active Threats: None detected
- Known Campaigns: No correlations
- Blacklist Status: 0 active blacklists
- Tor/Proxy: Not identified as Tor exit node, proxy, or VPN
Observation History
Eighteen total observations were recorded. Recent signals showed mixed geolocation data points between US (Boston) and India (Pune), with no evidence of persistent malicious activity or threat persistence. No campaign correlations were established.
Network Relationships
All relationship graph entries indicate same-network associations with MSFT infrastructure. No external entity links were identified beyond Microsoft's organizational network.
Neighborhood Analysis
The /24 subnet (20.193.226.228/24) demonstrated clean status with 0 abuse density. One neighboring IP (20.193.226.44) was observed with a risk score of 25, classified as low risk. No high or medium risk siblings were present in the immediate neighborhood.
Recommendations
The IP is classified as Microsoft Azure cloud infrastructure with moderate risk due to DNSBL listings. SOC analysts may consider:
- Monitoring for unusual outbound connections from this Azure endpoint
- Reviewing firewall rules against Microsoft Azure IP ranges per organizational policy
- No immediate blocking recommended; the IP is legitimate infrastructure with no active malicious indicators
Conclusion
20.193.226.228 represents legitimate Microsoft Azure cloud infrastructure. While flagged on some DNSBLs, no active threat indicators were observed. Standard monitoring is appropriate without immediate blocking action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 26% | 7 | 8 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-11 11:49:39 UTC |
| Last Seen | 2026-08-31 17:18:04 UTC |
| Profile Built | 2026-08-29 03:19:29 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.