# IP Intelligence Briefing: 20.240.235.182
Classification: Microsoft Azure Cloud Infrastructure
Risk Level: LOW (Score: 25/100)
Date: Current Observation Period
---
## Ownership & Network Attribution
The IP address 20.240.235.182/32 is registered to Microsoft Corporation (ASN 8075, MSFT) within the 20.192.0.0/10 block. The IP is classified as Microsoft Azure cloud compute infrastructure. No hosting, proxy, or VPN indicators present.
Geolocation: Stockholm, Sweden (SE)
Confidence: Medium (56%) via multi-signal inference
---
## Threat Profile
- Risk Score: 25 (Low Risk)
- Abuse Confidence: Not applicable
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listings: 1 (minimal impact)
- Known Campaigns: None detected
---
## Network Services
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Email Auth (SPF/DMARC): N/A (no hosted domains)
The IP is configured as a firewalled endpoint with no exposed services, consistent with Azure infrastructure backend connectivity.
---
## Temporal Analysis
Observation History: 14 signals recorded across August 13, 2026
Threat Persistence: None
Ownership Stability: Stable (Microsoft Azure)
Route Stability: Fluctuating (common for cloud providers)
Persistence Indicator: Not persistently malicious
Recent scans detected but show no escalating threat patterns.
---
## Neighborhood Assessment
Subnet: 20.240.235.182/24
Abuse Density: 0.0
Sibling IPs: 0 detected
Risk Distribution: No high-risk neighbors identified
The immediate /24 subnet shows no abuse activity.
---
## Relationships
- Primary Network: MSFT (Microsoft Azure)
- Linked Entities: Internal network relationships only
- External Hostnames/Certificates: None detected
---
## Recommended Actions
No blocking or mitigation actions recommended. The IP address is a legitimate Microsoft Azure infrastructure endpoint with no malicious indicators. Monitor as part of standard cloud provider traffic baseline.
SOC Analyst Notes: This IP represents Microsoft Azure backend connectivity. Traffic patterns should align with expected cloud service communication. No additional investigation required unless anomalous traffic behavior is observed from this address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-09 23:07:58 UTC |
| Last Seen | 2026-08-27 23:44:30 UTC |
| Profile Built | 2026-08-29 03:34:35 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.