IPDebrief

20.197.49.178

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 20.197.49.178/32

## Executive Summary

Risk Rating: Low Risk (Score: 25/100)

Classification: Legitimate Cloud Infrastructure (Microsoft Azure)

Recommendation: Monitor; No Action Required

## Ownership & Infrastructure

Organization: Microsoft Corporation (AS8075)

Network Block: 20.192.0.0/10 (MSFT)

Infrastructure Type: Microsoft Azure Cloud

Registration: ARIN Registry, 20.192.0.0/10 CIDR block

Geolocation: United States (Maharashtra/Pune region)

Accuracy Radius: 2,500 km

Geo-Validation: Plausible; ICMP blocked during validation

## Threat Assessment

Reputation Score: 25 (Low Risk)

Known Threat Indicators: None

Blacklist Status: Clean (0 entries)

Known Campaigns: None

Threat Feeds: No matches

Abuse Indicators:

DNSBL Listing: 1 listing detected (minimal impact)

## Network Services & DNS

Open Ports: None detected

TLS Certificate: Not configured

Hosted Domains: 0

PTR Records: None

Forward Resolution: 0 entries

Service Purpose: Firewalled / No Services

Email Reputation: No data available

## Control Plane Analysis

BGP Prefix: 20.192.0.0/10

Route Stability: False

Route Changes (30d): 0

RPKI State: Not assessed

MoAS (Multiple Origin ASN): No

DNSSEC Valid: True

Delegation Age: Not available

## Neighborhood Context

Subnet: 20.197.49.0/24

Abuse Density: 0 (mostly clean)

Total Siblings: 1

Active Siblings: 0

Threat Siblings: 1

Inherited Risk: 2

## Historical Observations

Total Signals: 44 observations recorded

Observation Period: 2026-06-20 through 2026-06-21

Trend: Consistent "Minimal" operator score (0.1304) across all observations

Risk Trend: Stable; no significant changes detected

Key Temporal Indicators:

## Related Entities

Relationship Count: 45 relationships identified

Primary Relationship Type: Same Network (MSFT)

Network Classification: Microsoft Azure infrastructure

## Behavioral Analysis

Honeypot Hits: 0

Enumeration Strikes: 0

WAF Violations: Not applicable

## Traceroute Analysis

Hop Count: 30

First Hop RTT: 0.2 ms

Last Hop RTT: 201.2 ms

Timed Out Hops: 16

Transit Networks: Comcast

## Recommended Actions

1. Allow Traffic: IP belongs to legitimate Microsoft Azure infrastructure; no blocking recommended

2. Monitor: Continue monitoring for behavioral changes or unexpected activity patterns

3. No Firewall Rules: No iptables/nftables rules required

4. Log Reference: Document as known Microsoft Azure IP for incident response context

## Intelligence Narrative

This IP address represents Microsoft Azure cloud infrastructure within the 20.192.0.0/10 block. The asset demonstrates a low-risk profile with no threat indicators, no blacklist associations, and a clean reputation across all threat feeds. Historical observation data shows consistent minimal operator scores, indicating stable, legitimate operation. The subnet exhibits minimal abuse density, and the IP has no active services exposedβ€”consistent with Microsoft's cloud infrastructure hardening practices. One DNSBL listing was identified, but this appears to be a minor administrative flag rather than an active threat indicator. SOC teams may safely allow traffic from this IP while maintaining standard monitoring protocols for any behavioral anomalies.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionMaharashtra
CityPune
Timezoneβ€”
Latitude18.52
Longitude73.85

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network NameMSFT
CIDR Block20.192.0.0/10
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
Cloud

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
13%
11
ownership
27%
23
reputation
26%
13
geolocation
30%
23
Overall23%914
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-06-05 01:01:51 UTC
Last Seen2026-06-26 18:12:22 UTC
Profile Built2026-06-27 11:10:21 UTC
Data FreshnessLive
Signal Types18
Total Observations45
πŸ” 18 signal types Β· 45 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.