# IP Intelligence Briefing: 20.195.181.145/32
Classification: Low Risk
Report Date: 2026-06-16
Analyst: Automated Intelligence System
---
## Executive Summary
IP 20.195.181.145 is a Microsoft Azure cloud infrastructure endpoint with a low risk profile (Risk Score: 25). The address is part of Microsoft's corporate network (ASN 8075) and is geolocated to São Paulo, Brazil. No active threat indicators, blacklisting, or malicious activity observed. The IP is properly classified as cloud compute infrastructure with firewalled services.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | Microsoft Corporation (MSFT) |
| **ASN** | 8075 |
| **CIDR Block** | 20.192.0.0/10 |
| **Network Role** | Microsoft Azure (CloudCompute) |
| **Geolocation** | São Paulo, SP, Brazil (BR) |
| **Coordinates** | -23.55, -46.63 |
| **Timezone** | America/Sao_Paulo |
| **Infrastructure Type** | Cloud Hosting |
---
## Risk Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
- Operator Score: 0.1304 (Minimal)
- Threat Indicators: None detected
- Known Attacker Status: False
- Tor Exit Node: False
- Spam Source: False
---
## Network Environment Analysis
Subnet Characteristics (20.195.181.0/24)
- Abuse Density: 33.33%
- Classification: Mostly Clean
- Total Siblings: 3
- Active Siblings: 1
- Threat Siblings: 1
- Inherited Risk Score: 2
Neighbor IPs (Low Risk)
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 20.195.181.7 | 25 | 50 |
| 20.195.181.226 | 25 | 50 |
Both neighboring IPs exhibit similar low-risk profiles consistent with Microsoft Azure infrastructure.
---
## Service Analysis
- Open Ports: None detected
- TLS Certificates: None
- HTTP Title: None
- Server Banner: None
- Service Status: Firewalled / No Services Running
This indicates the IP is behind cloud infrastructure firewalls with no publicly accessible services, consistent with Azure backend infrastructure.
---
## Historical Observation Analysis
Observation Count: 15 signals
Key Historical Findings:
- Ownership Changes: 0 (Stable ownership)
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: False
- Recent Activity: All observations from 2026-06-16 (current period)
- Geolocation Confidence: 56% (Multi-signal inference)
- Control Plane: Route changes: 0 (last 30 days), Stable routing
---
## Relationship Graph
Direct Relationships: 4
- All relationships classified as "Same Network" to MSFT
- No external entity associations detected
- No certificate or hostname relationships outside Microsoft network
---
## Control Plane Analysis
| Metric | Value |
|---|---|
| Origin ASN | 8075 |
| BGP Prefix | 20.192.0.0/10 |
| Route Changes (30d) | 0 |
| Route Stability | Stable |
| MOAS Status | False |
| DNSSEC Valid | True |
| IRR Consistency | N/A |
| RPKI State | N/A |
---
## Security Recommendations
Action Required: None
Rationale:
- Risk score of 25 indicates minimal threat
- No threat indicators or malicious activity detected
- No firewall rules or blocking recommendations generated
- IP is classified as legitimate Microsoft Azure infrastructure
SOC Analyst Guidance:
- No blocking or rate-limiting actions recommended
- No threat hunting priority assigned
- Standard cloud infrastructure monitoring applies
- Continue passive monitoring for any behavioral changes
---
## Conclusion
IP 20.195.181.145 represents standard Microsoft Azure cloud infrastructure with no malicious activity or threat indicators. The address is properly associated with Microsoft Corporation, maintains stable ownership, and operates within normal cloud compute parameters. No immediate security actions are required. Standard network monitoring protocols for cloud infrastructure should be maintained.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 24% | 2 | 2 |
| Overall | 22% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-09 02:10:11 UTC |
| Last Seen | 2026-06-21 15:40:46 UTC |
| Profile Built | 2026-06-21 15:43:16 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 17 |
Full dossier details are available via our API.