INTELLIGENCE BRIEFING: 20.215.189.213
Classification: Cloud Infrastructure / Moderate Risk (Score: 40)
Ownership & Infrastructure
- ASN 8075 (Microsoft Corporation), CIDR: 20.192.0.0/10
- Network Role: Microsoft Azure Cloud Compute infrastructure
- Classification: Cloud-hosted infrastructure with no exposed services or open ports
- Geolocation: Warsaw, Poland (PL) - Microsoft Azure region
Threat Assessment
- Reputation: Moderate Risk (Score 40)
- Threat Indicators: None detected
- Blacklist Status: Listed on 2 of 8 DNSBL entries (max severity: High)
- Control Plane: BGP prefix 20.192.0.0/10, route stability issues detected
- Abuse Density: Low (Subnet classification: mostly_clean)
Neighborhood Analysis
- /24 Subnet (20.215.189.0/24): Abuse density 1, mostly clean
- Risk Distribution: No high or medium risk neighbors identified
- Inherited Risk: 2 (minimal)
Observation History
- Total Observations: 18 signals across monitoring period
- Recent Activity (2026-08-12): Subnet classified as mostly_clean with abuse density 1
- Operator Score: 0.1304 (Minimal)
- DNSBL Listings: 2 confirmed listings with high severity designation
- No persistent malicious behavior detected
Technical Profile
- Services: No open ports, no TLS certificates, no HTTP services
- DNS: No PTR records, no forward resolution
- Traceroute: 23 hops, transit through Comcast network
- Fingerprint: No web server characteristics, no HSTS/CSP headers
Recommendations
- No immediate blocking required - IP belongs to legitimate Microsoft Azure infrastructure
- Monitor DNSBL listings for potential abuse complaints or reputation degradation
- Apply standard cloud infrastructure monitoring policies
- Consider allowing traffic if legitimate Azure services are expected
SOC Analyst Notes
This IP is identified as Microsoft Azure cloud infrastructure with moderate risk scoring primarily driven by DNSBL listings. The absence of open services and threat indicators suggests legitimate cloud hosting. Neighborhood analysis confirms the /24 subnet is classified as mostly clean. No active threat indicators or known malicious behavior observed. Routine monitoring recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 19% | 1 | 2 |
| Overall | 23% | 9 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 20:05:38 UTC |
| Last Seen | 2026-08-12 18:00:42 UTC |
| Profile Built | 2026-08-12 18:10:24 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.