INTELLIGENCE BRIEFING: IP 20.210.194.124/32
Classification: Microsoft Azure Cloud Infrastructure
Date: Analysis completed based on current threat intelligence
---
**EXECUTIVE SUMMARY**
IP 20.210.194.124 is a Microsoft Azure cloud compute endpoint (AS8075, MSFT) located in Tokyo, Japan. The IP presents a moderate risk profile (risk score: 40) with no active threat indicators. The address is classified as cloud infrastructure hosting multiple services, primarily HTTP (port 80) and SSH (port 22).
---
**OWNERSHIP & NETWORK IDENTIFICATION**
- Organization: Microsoft Corporation
- AS Number: 8075 (MSFT)
- Network Block: 20.192.0.0/10 (MSFT)
- Network Role: Microsoft Azure Cloud Compute, Multi-Service Host
- Infrastructure Type: Cloud compute environment
---
**THREAT ASSESSMENT**
Current Risk Profile: Moderate Risk (Score: 40)
| Metric | Status |
|---|---|
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| Blacklist Count | 0 |
| Campaign Matches | None |
DNSBL Status: Listed on 2 of 8 threat intelligence feeds.
Neighborhood Analysis: Subnet 20.210.194.124/24 shows clean classification with 0 abuse density. No threat siblings detected in the immediate /24 neighborhood.
---
**NETWORK SERVICES & FINGERPRINTING**
- HTTP (Port 80/TCP): nginx/1.24.0 on Ubuntu
- SSH (Port 22/TCP): OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
- TLS Certificate: None detected
- HTTP Status: 200 OK
- Header Order: Standard nginx response headers present
- Security Headers: No HSTS, CSP, or referrer policy headers configured
---
**GEOLOCATION DATA**
- Primary Location: Tokyo, Japan
- Geolocation Confidence: High (geoPlausible: true)
- Coordinate Distance: 9,212.3 km from reference point
- Minimum Possible RTT: 184.25ms
Note: Historical signals show conflicting geolocation data with low-confidence US placement (confidence: 0.35), but Japan remains the consensus location.
---
**OBSERVATION HISTORY**
Analysis of 19 historical observations reveals:
- Recent listing activity detected (3 of 8 lists flagged as high severity on 2026-08-13)
- Persistent HTTP service response with consistent nginx fingerprinting
- No evidence of malicious behavioral shifts
- Route stability flagged as false
---
**RELATIONSHIP GRAPH**
- 9 relationships identified to MSFT network resources
- All relationships classified as "Same Network"
- No external organizational or certificate correlations
---
**RECOMMENDATIONS**
No immediate blocking action required. The IP is legitimate Microsoft Azure infrastructure.
Defensive Considerations:
- Monitor for port 22 SSH activity from unexpected sources
- Verify legitimate Azure cloud usage patterns for this IP range
- Standard cloud security monitoring applies; no specialized threat response needed
Recommended Actions: None required based on current threat profile
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 23% | 2 | 2 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:50:09 UTC |
| Last Seen | 2026-08-13 12:53:10 UTC |
| Profile Built | 2026-08-13 00:19:39 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.