## INTELLIGENCE BRIEFING: 20.251.223.35
Classification: Low Risk / Cloud Infrastructure
Date: 2026-06-18
OVERVIEW
IP address 20.251.223.35 belongs to Microsoft Corporation (ASN: 8075, AS8075) and operates within Microsoft Azure cloud infrastructure. The IP demonstrates cloud compute characteristics with a risk score of 25 (Low Risk) and is classified as hosting infrastructure.
OWNERSHIP & INFRASTRUCTURE
- Organization: Microsoft Corporation
- ASN: 8075 (Microsoft)
- BGP Prefix: 20.192.0.0/10
- Network Role: Cloud Compute (Microsoft Azure)
- Infrastructure Type: Cloud Hosting
- Geolocation: US (data source consensus indicates Oslo region with 2500km accuracy radius)
THREAT ASSESSMENT
- Risk Score: 25/100
- Abuse Confidence: Null
- Blacklist Status: Listed on 8 DNSBLs with 1 high-severity listing (most recent: 2026-06-18)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Campaigns: None detected
NETWORK BEHAVIOR
- Open Ports: None detected
- Services: No active services (firewalled/no services)
- DNS Resolution: No PTR hostnames, forward resolution not confirmed
- TLS/HTTP: No certificates, HTTP headers, or web services detected
- WAF Violations: 0
- Honeypot Hits: 0
RELATIONSHIP ANALYSIS
- Network Relationships: 20 connections to Microsoft network (MSFT)
- Related Entities: All relationships indicate same network ownership
- Campaign Correlation: 0 correlated IPs, 0 certificate matches
SUBNET NEIGHBORHOOD
- Subnet: 20.251.223.0/24
- Abuse Density: 0 (mostly clean)
- Threat Siblings: 1 (within /24)
- Active Siblings: 1
SIGNAL HISTORY (23 Observations)
Recent observations (2026-06-18) show:
- Operator score: 0.1304 (Minimal)
- One high-severity blacklist listing detected
- Mixed proxy/VPN detection signals in historical data
- Ownership changes: 0 (stable)
- Threat observation count: 1
RECOMMENDATIONS
No immediate blocking actions required. This IP is Microsoft Azure infrastructure with low risk characteristics. Monitor for:
1. Any new high-severity blacklist listings
2. Behavioral changes from cloud hosting profile
3. Emergence of open ports/services
Defense Posture:
- Allow traffic from Microsoft Azure ranges if business requirements exist
- No specific firewall rules recommended
- Maintain standard cloud provider egress/ingress policies
INTELLIGENCE SUMMARY
20.251.223.35 is legitimate Microsoft Azure cloud infrastructure with minimal threat indicators. The single high-severity blacklist listing appears to be a false positive given the established cloud provider reputation. No blocking recommended. Monitor for behavioral deviations from cloud hosting norms.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:08 UTC |
| Last Seen | 2026-06-27 03:43:03 UTC |
| Profile Built | 2026-06-27 21:49:08 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.