# IP Intelligence Briefing: 20.251.117.149/32
Classification: Cloud Infrastructure IP (Microsoft Azure) β Moderate Risk
Date: Analysis based on current IPDebrief data
---
## Executive Summary
IP 20.251.117.149 is a Microsoft Azure cloud compute infrastructure address assigned to ASN 8075 (MSFT). The IP carries a moderate risk score of 50 and shows no active threat indicators in current threat feeds. However, historical signal data indicates the IP has been classified as a proxy/compromised server by at least one reputation source, and the address is listed on two DNS blacklists. Geo-locational data shows inconsistencies between US and Norway (Trondheim) assignments.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 20.251.117.149/32 |
| **Organization** | Microsoft Corporation |
| **ASN** | 8075 |
| **CIDR Block** | 20.192.0.0/10 |
| **Infrastructure Type** | Cloud Compute (Azure) |
| **Country** | US (primary) / Norway (secondary) |
| **Geolocation** | Trondheim, Norway / United States (conflicting data) |
| **Network Role** | Cloud Hosting / Azure CDN |
| **Risk Score** | 50 (Moderate) |
---
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 2 (of 8 total lists)
- Threat Feeds: None active
- Known Campaigns: None
- Abuse Confidence Score: Not calculated
---
## Neighborhood Analysis
- Subnet: 20.251.117.149/24
- Abuse Density: 0 (clean subnet)
- Threat Siblings: 0
- Active Siblings: 0
- Total Siblings: 0 (isolated /24)
The IP exists in a relatively clean subnet with no adjacent threat activity detected.
---
## Signal History (15 Observations)
Recent signal history reveals:
- Ownership: Stable (Microsoft Corporation)
- Geolocation: Inconsistent β US (ARIN) and Norway/Trondheim signals present
- Proxy Classification: One signal (proxycheck-io) flagged IP as proxy/compromised server with 100% risk
- Malicious Activity: Not persistently malicious
- Threat Persistence: 0 days
---
## Related Entities
- Network: MSFT (Microsoft Corporation)
- Relationships: Same Network classification only
---
## Recommended Actions
Based on the moderate risk profile (50/100), the following firewall rules are recommended for defensive implementation:
```bash
# iptables
iptables -A INPUT -s 20.251.117.149 -j DROP
# nftables
nft add rule inet filter input ip saddr 20.251.117.149 drop
# nginx
deny 20.251.117.149;
# pfSense
20.251.117.149/32
# Cloudflare WAF
Expression: ip.src eq 20.251.117.149
# AWS WAF
Addresses: 20.251.117.149/32
```
---
## Intelligence Assessment
This IP belongs to Microsoft Azure's 20.192.0.0/10 block, a legitimate cloud infrastructure range. The moderate risk score (50) is driven by:
1. DNS blacklist presence (2/8 lists)
2. Conflicting geolocation data
3. Historical proxy classification signals
No active exploitation or malicious activity currently detected. The IP appears in a clean neighborhood with no threat siblings. However, the conflicting geolocation and proxy signals warrant continued monitoring if this IP begins interacting with your network.
Recommendation: Implement the provided firewall rules as defensive measures. Monitor for any behavioral changes or increased interaction with your infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.192.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 0% | 0 | 0 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-17 19:05:03 UTC |
| Last Seen | 2026-06-25 01:47:53 UTC |
| Profile Built | 2026-06-22 02:15:42 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.