# IP INTELLIGENCE BRIEFING: 20.223.230.113/32
## Executive Summary
IP address 20.223.230.113 is classified as Low Risk (Risk Score: 25) with a reputation profile consistent with legitimate Microsoft Azure cloud infrastructure. No active threat indicators, malicious behavior, or attack campaigns detected.
---
## Infrastructure Profile
Ownership & Network Classification:
- ASN: AS8075 (Microsoft Corporation)
- Organization: Microsoft Corporation
- Infrastructure Type: CloudCompute (Microsoft Azure)
- BGP Prefix: 20.192.0.0/10
- Network Role: Cloud hosting environment with firewalled/no services exposed
Geolocation:
- Country: Ireland (IE)
- City: Dublin
- Coordinates: 53.35°N, -6.26°W
- Timezone: Europe/Dublin
---
## Threat Assessment
Current Risk Indicators:
- Risk Score: 25/100 (Low Risk)
- Abuse Confidence: Not applicable (legitimate infrastructure)
- Blacklist Status: Listed on 1 of 8 DNSBLs (minimal impact)
- Known Campaigns: None detected
- Threat Feeds: No matches
- Known Attacker: False
Service & Port Exposure:
- Open Ports: None detected
- HTTP/HTTPS Services: Not exposed
- TLS Certificates: None
- Server Banner: Not available
---
## Operational History
Observation Timeline: 19 historical observations recorded
Key Historical Signals:
- June 14, 2026: Confirmed Microsoft Azure cloud infrastructure
- June 18, 2026: Network scanning activity (routine infrastructure assessment)
- June 19, 2026: Microsoft Corporation ASN attribution (AS8075)
Behavioral Indicators:
- Threat persistence days: 0
- Is persistently malicious: False
- Honeypot hits: 0
- WAF violations: 0
- Enumeration strikes: 0
Temporal Stability: No ownership changes detected; consistent Microsoft infrastructure assignment.
---
## Neighborhood Analysis
Subnet Assessment (20.223.230.113/24):
- Abuse Density: 0 (clean subnet)
- Classification: Mostly clean
- Total Siblings: 1
- Active Siblings: 0
- High/Medium Risk Neighbors: 0
The /24 subnet shows minimal abuse activity, consistent with Microsoft Azure's enterprise cloud hosting environment.
---
## Relationship Graph
Network Associations: 13 relationships identified
- All relationships mapped to Microsoft (MSFT) network segments
- Consistent Microsoft ecosystem footprint
- No connections to external threat actors or suspicious entities
---
## Recommended Actions
Security Recommendations: None required
Rationale: This IP address represents legitimate Microsoft Azure cloud infrastructure with no malicious indicators. Standard operational security practices apply. No firewall rules or blocking actions recommended.
Monitoring Considerations: Continue routine monitoring for any changes in infrastructure behavior or service exposure patterns.
---
## Intelligence Narrative
IP 20.223.230.113 operates as Microsoft Azure cloud infrastructure located in Dublin, Ireland. The address carries a low-risk profile with a score of 25, consistent with Microsoft's enterprise cloud hosting operations. Historical observations confirm consistent Microsoft ownership (AS8075) and cloud infrastructure classification since at least June 2026. No threat indicators, attack campaigns, or malicious behavior have been observed across 19 historical signal observations. The adjacent /24 subnet demonstrates minimal abuse activity, reinforcing the legitimate infrastructure classification. The IP is currently listed on a single DNSBL with negligible operational impact. SOC teams should classify this as benign Microsoft cloud infrastructure requiring standard operational monitoring without defensive blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:08 UTC |
| Last Seen | 2026-06-27 03:34:41 UTC |
| Profile Built | 2026-06-27 21:40:58 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.