## IP Intelligence Briefing: 20.198.117.188
Date: 2026-08-13
Classification: Microsoft Azure Cloud Infrastructure
Risk Assessment: Moderate Risk (65/100)
Executive Summary
IP 20.198.117.188 is assigned to Microsoft Corporation (AS8075) within the Microsoft Azure cloud infrastructure block (20.192.0.0/10). The IP demonstrates moderate risk scoring consistent with cloud hosting environments, with no active malicious indicators detected.
Technical Profile
- Organization: Microsoft Corporation
- ASN: AS8075 (MSFT)
- CIDR Block: 20.192.0.0/10
- Network Role: Cloud Compute (Microsoft Azure)
- Geolocation: Pune, Maharashtra, India (consensus geolocation)
- Infrastructure Type: Cloud hosting with firewall protection
- Services: No open ports or active services detected
- DNS: No PTR records, no forward resolution
Threat Indicators
- Abuse Confidence Score: Not available
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: Listed on 3 out of 8 DNSBLs
- Threat Feeds: No active correlations
- Campaign Association: None detected
Network Neighborhood Analysis
Subnet: 20.198.117.188/24
- Abuse Density: 0
- Threat Siblings: 0 of 1 total sibling IPs
- Classification: Clean
- Inherited Risk: 0
The /24 subnet shows no neighboring threats, suggesting isolated cloud infrastructure behavior rather than coordinated malicious activity.
Historical Observations
Total Observations: 15
- Recent subnet classification: "clean" with 0 abuse density
- Geolocation signals show conflicting data (India vs. US coordinates with 0.35 confidence)
- No persistent malicious behavior detected
- Ownership stability: No changes recorded
Recommended Actions
Risk Score: 65/100 triggers elevated monitoring requirement
1. Monitoring Priority: Increase logging verbosity for traffic from this IP and review recent activity patterns
2. Firewall Configuration: The risk score suggests implementing blocking rules if this IP is not recognized as legitimate Azure traffic
3. Contextual Analysis: Verify if this IP corresponds to expected Microsoft Azure service endpoints for your organization
Firewall Rules (if blocking required)
```
iptables: iptables -A INPUT -s 20.198.117.188 -j DROP
nftables: nft add rule inet filter input ip saddr 20.198.117.188 drop
nginx: deny 20.198.117.188;
```
Analyst Notes
This IP belongs to Microsoft's enterprise cloud infrastructure block. The moderate risk score (65) likely reflects Azure's reputation-based scoring rather than malicious activity. Legitimate Azure users may encounter this IP for cloud services, API calls, or automated processes. Consider whitelisting if traffic patterns align with expected Azure service usage. The absence of open ports and services indicates proper firewall hardening typical of cloud infrastructure.
Recommendation: Monitor rather than block unless specific malicious activity is confirmed through correlation with other threat intelligence sources.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-12 12:21:25 UTC |
| Last Seen | 2026-08-31 17:18:04 UTC |
| Profile Built | 2026-08-30 19:26:40 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.