IPDebrief

20.228.133.97

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 20.228.133.97/32

Classification: LOW RISK – Legitimate Cloud Infrastructure

Analysis Date: 2026-06-15

Source: IPDebrief Intelligence Platform

---

## Executive Summary

IP address 20.228.133.97 is identified as Microsoft Corporation cloud infrastructure (Microsoft Azure). The IP carries a risk score of 25 (Low Risk) and shows no active threat indicators. The address is part of Microsoft's AS8075 network and is classified as cloud compute infrastructure. No malicious activity, campaigns, or threat correlations were detected.

---

## Ownership and Infrastructure

AttributeValue
**Organization**Microsoft Corporation
**ASN**8075
**Infrastructure Type**CloudCompute
**Network Role**Microsoft Azure
**Provider**Microsoft Azure
**Country**US
**Region**Virginia
**CIDR Block**20.228.133.0/24
**BGP Prefix**20.192.0.0/10

---

## Risk Assessment

---

## Network Behavior

The IP is configured with firewalled/no services posture, consistent with cloud infrastructure that may not expose public-facing services from this specific endpoint.

---

## Control Plane Analysis

---

## Temporal Analysis

The IP has demonstrated consistent ownership and infrastructure classification with no observed malicious behavior over the observation period.

---

## Geographic Data

---

## Neighborhood Analysis (20.228.133.0/24)

The immediate /24 subnet shows minimal abuse density, consistent with Microsoft's legitimate cloud infrastructure.

---

## Relationship Graph

The IP maintains 11 network relationships, all identified as "Same Network" with MSFT (Microsoft Corporation), confirming the IP's integration within Microsoft's broader network infrastructure.

---

## Observation History

Total observations: 18

Key observations:

---

## Recommended Actions

Action TypeRecommendation
**Firewall**No blocking required – legitimate cloud infrastructure
**Monitoring**Standard monitoring appropriate
**Threat Intel**No threat indicators present
**Reputation**Low risk – maintain current classification

Note: While the control plane data indicates 1 DNSBL listing among 8 total lists, the overall threat assessment remains LOW RISK. This discrepancy warrants continued monitoring but does not currently indicate malicious activity.

---

## Conclusion

IP 20.228.133.97 represents legitimate Microsoft Azure cloud infrastructure with no evidence of malicious activity. The IP demonstrates stable ownership, consistent geographic attribution to Virginia, and clean neighborhood metrics. No security actions or blocking are recommended. Standard monitoring practices should be maintained.

Analyst Notes: This IP should be treated as trusted infrastructure. If this IP appears in threat feeds or incident reports, investigate the context of those reports against this baseline profile.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVA
CityVirginia
TimezoneAmerica/New_York
Latitude37.37
Longitude-79.46

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
8%
11
services
12%
22
ownership
20%
23
reputation
28%
13
geolocation
25%
22
Overall20%1015
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-21 08:55:09 UTC
Last Seen2026-06-28 13:11:49 UTC
Profile Built2026-06-29 07:17:07 UTC
Data FreshnessLive
Signal Types19
Total Observations22
πŸ” 19 signal types Β· 22 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.