## INTELLIGENCE BRIEFING: 20.197.177.179
Classification: LOW RISK โ Legitimate Cloud Infrastructure
Date of Assessment: 2026-06-14
---
EXECUTIVE SUMMARY
IP 20.197.177.179 is a Microsoft Azure cloud compute endpoint located in São Paulo, Brazil. The asset presents LOW RISK (Score: 25) with no active threat indicators, campaigns, or malicious reputation. Infrastructure is classified as Microsoft Azure CloudCompute with firewalled/no services detected.
---
OWNERSHIP & INFRASTRUCTURE
- Organization: Microsoft Corporation (AS8075)
- Infrastructure Type: CloudCompute
- Provider: Microsoft Azure
- Geolocation: São Paulo, SP, Brazil (BR)
- Network Classification: Cloud infrastructure, not CDN/VPN/proxy
- Stability: Stable ownership, no recent changes
---
THREAT ASSESSMENT
- Risk Score: 25/100 (Low Risk)
- Abuse Confidence: None detected
- Threat Indicators: 0 active indicators
- Blacklist Status: Listed on 1 of 8 DNSBL lists (minor concern, typical for cloud infrastructure)
- Campaign Associations: None detected
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
---
NEIGHBORHOOD ANALYSIS
Subnet: 20.197.177.0/24
- Abuse Density: 0% (mostly_clean classification)
- Total Siblings: 4
- Active Siblings: 1
- Threat Siblings: 1
- Risk Distribution: 3 low risk, 0 medium/high risk
Neighbor IPs:
- 20.197.177.196 (Risk: 25)
- 20.197.177.210 (Risk: 25)
- 20.197.177.252 (Risk: 25)
---
OBSERVATION HISTORY
- Total Observations: 21
- Recent Activity: 2026-06-14
- Threat Persistence: 0 days
- Classification Consistency: Cloud infrastructure classification maintained across observations
- Signal Types: Provider classification, geolocation inference, operator score assessment
- Trend: No degradation in risk profile; consistent cloud infrastructure behavior
---
RELATIONSHIP GRAPH
- Total Relationships: 20
- Relationship Type: Same Network (MSFT)
- Linked Entities: Microsoft network infrastructure (all relationships point to MSFT)
- Network Classification: Part of Microsoft corporate network
---
SECURITY ACTIONS & RECOMMENDATIONS
Recommended Action: NO BLOCKING REQUIRED
Rationale:
1. Legitimate Microsoft Azure cloud infrastructure
2. Low risk profile with no threat indicators
3. Clean neighborhood with minimal abuse density
4. One DNSBL listing (likely infrastructure-related, not malicious)
5. No evidence of malicious activity in history or relationships
Firewall Rule: Allow (no restrictions needed for cloud infrastructure)
---
INTELLIGENCE NOTES
- IP is part of Microsoft's cloud compute network serving São Paulo region
- DNSBL listing is minor concern and does not indicate active threat
- No correlation with known APT campaigns or malicious actors
- Infrastructure behavior consistent with legitimate cloud provider
- SOC analysts may classify as trusted cloud infrastructure with no additional monitoring required
END BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-13 12:50:06 UTC |
| Last Seen | 2026-06-27 23:34:35 UTC |
| Profile Built | 2026-06-28 23:40:39 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.