# IP Intelligence Briefing: 20.89.226.146/32
Classification: Cloud Infrastructure (Microsoft Azure) | Risk Level: Low | Status: Active Monitoring
---
## Executive Summary
IP address 20.89.226.146 is a Microsoft Corporation-owned cloud compute resource deployed within Microsoft Azure infrastructure. The IP demonstrates consistent association with legitimate cloud services and presents no active threat indicators. Risk assessment indicates low-risk classification with stable network routing and no malicious behavior observed.
---
## Ownership & Network Classification
- Organization: Microsoft Corporation (ASN: 8075)
- Network Role: Cloud Compute (Microsoft Azure)
- Infrastructure Type: Cloud-hosted infrastructure with firewall protection
- Classification Flags: is_cloud: true, is_hosting: true, is_cdn: false, is_vpn: false, is_proxy: false
- BGP Prefix: 20.64.0.0/10 (origin: AS8075)
- Route Stability: Stable routing with no route changes in 30 days
---
## Geolocation Data
- Country: Japan (JP)
- Region: 27 (Osaka)
- Coordinates: 34.69°N, 135.5°E
- Timezone: Asia/Tokyo
- Geolocation Consensus: Multiple signals confirm Japan location
- Accuracy Radius: 150 km
---
## Threat Intelligence Assessment
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable (no abuse signals)
- Blacklist Status: Not listed on any known threat feeds
- Threat Indicators: None detected
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Behavioral Observations:
- No WAF violations recorded
- No honeypot hits
- No enumeration strikes
- Zero total incidents reported
---
## Network Services & DNS
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None active
- DNS PTR Records: None
- Forward Resolution: None
- Hosted Domains: Zero
- Email Authentication: No SPF/DMARC records configured
---
## Subnet Neighborhood Analysis (20.89.226.0/24)
- Subnet Classification: Mostly Clean
- Abuse Density: 0.0 (minimal abuse activity)
- Total Sibling IPs: 2
- Active Siblings: 1
- Threat Siblings: 2
- Inherited Risk: 5
Notable Neighbor:
- 20.89.226.144: Risk score 25, Authority score 50 (same Microsoft infrastructure class)
---
## Historical Timeline
Recent observation history reveals consistent Microsoft Azure infrastructure classification:
- June 2026: Multiple signals confirm cloud infrastructure classification, Osaka geolocation, and Microsoft ASN association
- Signal Persistence: Threat observation count: 1 (isolated signal)
- Ownership Stability: No ownership changes recorded
- Risk Trend: Stable with no escalation patterns
---
## Recommended Security Actions
Current Status: No specific firewall rules or blocking actions required.
Recommended Monitoring:
- Continue monitoring for service changes on previously unmonitored ports
- Observe for any deviation from Microsoft Azure network behavior patterns
- Monitor for unexpected DNS resolution activity
- Track for emergence of open ports or HTTP/TLS services
Contextual Note: As a Microsoft Azure infrastructure IP, this address represents legitimate cloud services. Any suspicious activity originating from this IP should be evaluated against Microsoft's legitimate service patterns rather than treated as inherently malicious.
---
## Conclusion
20.89.226.146/32 is a low-risk Microsoft Azure cloud infrastructure IP with no active threat indicators. The subnet demonstrates minimal abuse density and the IP shows consistent association with legitimate cloud services. Routine monitoring is sufficient; no immediate blocking or mitigation actions are warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | โ |
| CIDR Block | 20.64.0.0/10 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 44% | 2 | 7 |
| routing | 20% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 25% | 11 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 23:49:40 UTC |
| Last Seen | 2026-06-28 10:36:24 UTC |
| Profile Built | 2026-06-29 04:40:50 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.