Your IP: 216.73.216.123
π€ Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.
IP Intelligence Briefing: 20.79.176.87
Date: 2026-06-16
---
**1. Core Profile**
- Reputation: Moderate Risk (Risk Score: 50)
- Ownership: Microsoft Corporation (ASN: 8075, Netname: MSFT)
- Geolocation: Registered to Dublin, Ireland (DE) | Coordinates Unavailable
- Network Role: Microsoft Azure Cloud Compute | Firewalled / No Services
- Threat Indicators: No active malware, C2, or spam sources detected.
---
**2. Threat Observations**
- DNSBL Listings: Flagged by 2/8 DNSBLs (low-severity).
- Behavioral Data: No honeypot hits, enumeration strikes, or WAF violations.
- Routing: BGP prefix `20.64.0.0/10` | Route stability: Unstable (fluctuations in transit networks).
- TLS/Certificates: No TLS certs or HTTP services detected.
---
**3. Historical Trends**
- Recent Activity: Subnet `20.79.176.87/24` shows clean abuse density (0/100).
- Ownership Stability: No changes in ownership over 30 days.
- Threat Persistence: No persistent malicious activity observed.
---
**4. Network Relationships**
- Linked Entities: Directly tied to Microsoft Azure infrastructure.
- Subnet Peers: No neighboring IPs in the `/24` subnet (0 active siblings).
- Abuse Density: Subnet classified as clean with no threat siblings.
---
**5. Recommendations**
- Monitor: Track DNSBL flags and BGP route stability for anomalies.
- Verify: Cross-check DNSBL entries with Microsoftβs abuse reports.
- Mitigate: Consider rate-limiting or blocking if this IP correlates with future threats.
- Investigate: Validate if the DNSBL flags relate to accidental spam or misconfigured services.
---
Source: IPDebrief Threat Intelligence Platform
Note: This IP is part of a legitimate cloud providerβs infrastructure but warrants monitoring due to marginal DNSBL flags.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.33.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
CN=amal.tunnel.orx.ma
Issued by CN=amal.tunnel.orx.ma
Self-signed: Yes
| SANs | None |
| Valid From | 2026-06-15T01:33:23+00:00 |
| Valid Until | 2027-06-15T01:33:23+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 7C6AC74D98A671A0A67DB5D063FFCFF31CB23F99 |
| Thumbprint | 140B4AE83D175719D4BA7A9409910AD0AB12A2D3 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 26% | 9 | 13 |
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-09 20:27:15 UTC |
| Last Seen | 2026-06-21 16:43:23 UTC |
| Profile Built | 2026-06-21 16:48:32 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
π 18 signal types Β· 20 observations collected
This report is generated from 18+ independent intelligence signals including
ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds,
behavioral fingerprinting, and more.
Full dossier details are available via our API.
Full dossier details are available via our API.
βΉοΈ About This Report
All data shown is publicly available network metadata β IP addresses do not reliably identify individuals.
Assessments are probabilistic and should not be used as sole basis for access control decisions.
To report an issue or request data review, contact admin@ipdebrief.com.