INTELLIGENCE BRIEFING: 20.226.5.174/32
EXECUTIVE SUMMARY
IP 20.226.5.174 is classified as a Microsoft Azure cloud infrastructure endpoint with moderate risk designation (65). The address demonstrates no active service exposure but shows behavioral patterns consistent with automated enumeration activity. No direct threat indicators or campaign associations identified.
OWNERSHIP & INFRASTRUCTURE
- Organization: Microsoft Corporation (AS8075)
- Network Block: 20.192.0.0/10 (Microsoft Azure)
- Infrastructure Type: Cloud Provider
- Service Status: Firewalled/No Services Detected
GEOLOCATION ANALYSIS
Current profile indicates São Paulo, Brazil (SP). Historical signals show geolocation inconsistencies, with earlier observations placing the endpoint in the United States. Route stability flagged as false, suggesting potential infrastructure changes or routing anomalies.
THREAT PROFILE
- Risk Score: 65 (Moderate)
- Blacklist Status: Listed on 3 of 8 DNSBLs
- Threat Indicators: None (not Tor exit, not known attacker, not spam source)
- Behavioral Flags:
- 15 enumeration strikes recorded
- Auto-banned status: Active
- Zero open ports identified
- Zero TLS certificates detected
NETWORK NEIGHBORHOOD
Subnet 20.226.5.0/24 analyzed:
- Total Siblings: 2
- Abuse Density: 0
- Neighbor 20.226.5.209: Risk Score 25 (Low threat)
- No high-risk adjacent addresses detected
OBSERVATION HISTORY
19 signal observations recorded. Most recent activity shows:
- Network classification: "mostly_clean" with 0.5 abuse density
- Ownership changes: 0
- Threat persistence: 0 days
- No confirmed malicious campaigns
ASSOCIATED ENTITIES
No relationship links detected (no hostnames, certificates, or related organizations).
RECOMMENDED ACTIONS
Based on moderate risk classification and enumeration activity:
1. Monitor โ Observe for service emergence or port opening
2. Block if โ Enumeration attempts detected from internal network
3. Allow if โ Legitimate Azure service communication verified via application layer inspection
THREAT ASSESSMENT
This IP represents legitimate cloud infrastructure with benign characteristics. Risk elevation stems from DNSBL listings and automated enumeration activity rather than confirmed malicious behavior. No immediate blocking required; maintain monitoring for service changes or behavioral shifts.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
| Enumeration | Path/resource enumeration | 5 |
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 10:06:36 UTC |
| Last Seen | 2026-08-12 22:25:42 UTC |
| Profile Built | 2026-08-12 22:28:13 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 27 |
Full dossier details are available via our API.