# IP INTELLIGENCE BRIEFING: 20.199.160.17/32
## Executive Summary
Target IP 20.199.160.17 is a low-risk Microsoft Azure cloud infrastructure asset. Overall risk score of 25 (Low Risk) with minimal threat indicators. No active malicious campaigns or known attacker associations detected.
## Infrastructure Profile
- IP Address: 20.199.160.17
- Organization: Microsoft Corporation (AS8075)
- Network Block: 20.192.0.0/10
- Provider: Microsoft Azure (CloudCompute infrastructure)
- Geolocation: US (primary), with Zurich CH geolocation signals
- Classification: Cloud hosting environment
## Threat Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable (legitimate cloud infrastructure)
- Known Attacks/Campaigns: None detected
- Tor/Proxy/Vpn: Not associated
- Spam Source: Not flagged
- Blacklist Status: 0 blacklists; 1 DNSBL listing among 8 total lists (minimal concern for cloud infrastructure)
## Network Services
- Open Ports: TCP 3389 (RDP)
- DNS Records: No PTR hostnames, no email authentication (SPF/DMARC)
- Infrastructure Type: Single-service host, cloud compute
## Neighborhood Analysis (20.199.160.17/24)
- Abuse Density: 1 (low)
- Classification: Mostly clean
- Threat Siblings: 1
- Active Siblings: 1
- Total Siblings: 1
- Inherited Risk: 2 (low)
## Control Plane Intelligence
- Origin ASN: AS8075
- BGP Prefix: 20.192.0.0/10
- RPKI State: Not assessed
- Route Stability: Not stable (expected for cloud infrastructure)
- Route Changes (30d): 0
- DNSSEC: Valid
## Historical Signal Observations
Analysis of 20 historical observations reveals:
- Primary Classification: Cloud infrastructure (Microsoft Azure)
- Provider Consistency: Microsoft Azure across all signals
- Location Variance: Mixed geolocation signals (US and CH/Zurich)
- Threat Persistence: 1 threat observation recorded; not persistently malicious
- Recent Activity: Signals observed on 2026-06-20 with confidence levels 0.35-0.85
## Relationship Mapping
- Network Associations: 20 relationships identified, all linked to MSFT (Microsoft network)
- Entity Types: Network relationships to Microsoft infrastructure
- No External Correlations: No certificate or organization links outside Microsoft ecosystem
## Recommended Security Actions
- Block Action: Not recommended (legitimate cloud infrastructure)
- Monitor: Standard cloud traffic monitoring
- Firewall Rules: None generated (low risk profile)
- Risk-Based Mitigation: No action required at this time
## Intelligence Conclusion
IP 20.199.160.17 represents legitimate Microsoft Azure cloud infrastructure with minimal threat posture. The single DNSBL listing is consistent with cloud hosting environments and does not indicate malicious activity. The open RDP port (3389) is typical for cloud infrastructure but warrants standard security monitoring. No blocking or mitigation actions recommended. Continue standard cloud traffic observation protocols.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | β |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-25 00:41:06 UTC |
| Last Seen | 2026-06-29 00:55:55 UTC |
| Profile Built | 2026-06-29 06:58:41 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.