## INTELLIGENCE BRIEFING: 20.205.17.105/32
EXECUTIVE SUMMARY
IP address 20.205.17.105 was analyzed on 2026-06-19. The IP is owned by Microsoft Corporation (ASN 8075) and operates within Microsoft Azure cloud infrastructure in Hong Kong. Overall risk assessment classified as Low Risk (score: 25). No active malicious indicators or threat associations were detected.
---
OWNERSHIP AND GEOLOCATION
- Organization: Microsoft Corporation
- ASN: 8075
- Country: Hong Kong (HK)
- Region: Hong Kong
- Network Role: Microsoft Azure CloudCompute infrastructure
- Infrastructure Type: Cloud hosting environment
- Registration: ARIN RIR
RISK ASSESSMENT
- Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Abuse Confidence Score: Not applicable
- Threat Indicators: None detected
- Blacklist Count: 0
- Known Campaigns: None
NETWORK CLASSIFICATION
- Is Cloud: Yes (Microsoft Azure)
- Is CDN: No
- Is VPN: No
- Is Proxy: No
- Is Tor Exit: No
- Is Hosting: Yes
- Is Residential: No
- Is Mobile: No
- BGP Prefix: 20.192.0.0/10
- AS Path: 34549 8075
- Route Stability: Stable
- RPKI State: Validated
NETWORK SERVICES
- Port 80/TCP: HTTP service active
- Port 22/TCP: SSH service active
- Server Banner: nginx/1.18.0 (Ubuntu)
- HTTP Version: 1.1
- TLS Certificate: None detected
DNS ANALYSIS
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Authentication: SPF/DMARC not configured
- DNSBL Listings: 1 out of 8 total lists
THREAT OBSERVATIONS
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Threat Feeds: None
- Campaign Likelihood: None
- Correlated IPs: 0
- Banner Matches: 0
- Certificate Matches: 0
OBSERVATION HISTORY
Analysis of 24 historical observations spanning from 2026-06-14 to 2026-06-19 indicates consistent Microsoft Azure infrastructure classification. No persistent malicious behavior was observed. The IP has maintained stable ownership with zero ownership changes recorded. Threat observation count: 1. The IP is not classified as persistently malicious.
NEIGHBORHOOD ANALYSIS
- Subnet: 20.205.17.105/24
- Abuse Density: 1 (mostly_clean classification)
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Risk Distribution: No high-risk neighbors detected
RELATIONSHIP GRAPH
The IP maintains 22 relationships, all classified as "Same Network" with target value "MSFT" (Microsoft Corporation). This confirms the IP operates within Microsoft's network infrastructure ecosystem.
RECOMMENDED ACTIONS
No specific remediation actions were required based on the risk profile. The IP operates within legitimate cloud infrastructure with no indicators of malicious activity. Standard monitoring practices are recommended.
---
ANALYST NOTES
This IP address represents legitimate Microsoft Azure cloud infrastructure. The low risk score and absence of threat indicators suggest normal cloud service operation. The single DNSBL listing and inherited risk score of 2 from subnet peers warrant continued monitoring but do not indicate immediate threat. No firewall rules or blocking actions are recommended at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | โ |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | โ |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.18.0 (Ubuntu) |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 24% | 2 | 3 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 27% | 11 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-13 19:04:43 UTC |
| Last Seen | 2026-06-27 23:46:30 UTC |
| Profile Built | 2026-06-28 17:50:55 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.