# IP Intelligence Briefing: 20.9.85.55
## Executive Summary
IP address 20.9.85.55 is a Microsoft Corporation (ASN 8075) Azure cloud infrastructure endpoint located in Des Moines, Iowa, United States. The IP presents a Moderate Risk profile (Score: 65) with no active malicious indicators. The address is associated with legitimate cloud compute services and shows consistent historical behavior with no evidence of persistent malicious activity.
## Technical Profile
Ownership & Classification
- Organization: Microsoft Corporation
- ASN: 8075 (MSFT)
- Network Block: 20.0.0.0/11
- Infrastructure Type: CloudCompute (Microsoft Azure)
- CIDR Classification: Cloud infrastructure endpoint
Geolocation
- Country: United States (US)
- Region: Iowa
- City: Des Moines
- Geographic Consensus: Valid (GeoPlausible: true)
- Accuracy Radius: 2,500 km
Network Services
- Open Ports: None detected
- HTTP/HTTPS: No services exposed
- TLS Certificates: None
- DNS Resolution: No forward resolution
- Email Auth: No SPF/DMARC records
- Connection Type: Firewalled/No Services
## Threat Assessment
Risk Indicators
- Risk Score: 65 (Moderate)
- Abuse Confidence: Not applicable (cloud infrastructure)
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Data
- DNSBL Listings: 3 out of 8 total lists
- Route Stability: Prefix not stable (route changes observed)
- RPKI State: Not available
- Operator Score: 0.1304 (Minimal)
## Historical Analysis
The IP has 15 historical observations spanning recent activity. Analysis reveals:
- Ownership Stability: No ownership changes detected
- Threat Persistence: Zero threat observation count
- Geolocation Consistency: Des Moines, Iowa coordinates maintained across observations
- Recent Activity: ICMP validation blocked, suggesting active network filtering
- Temporal Pattern: No evidence of becoming more or less risky over time
## Network Neighborhood
- Subnet: 20.9.85.0/24
- Abuse Density: 0 (low)
- Neighbor Count: 1
- Neighbor IP: 20.9.85.117 (Risk Score: 25, Authority Score: 50)
- Threat Siblings: 0
## Intelligence Relationships
The IP exhibits two "Same Network" relationships to MSFT organization identifiers, confirming consistent cloud infrastructure classification.
## Recommended Actions
Based on the risk profile and classification:
1. No immediate blocking required β IP is legitimate Microsoft Azure infrastructure
2. Monitor DNSBL activity β 3 listings detected; investigate if traffic patterns correlate with listed sources
3. Allow standard cloud traffic β No evidence of malicious activity
4. No firewall rules needed β Services are already firewalled with no open ports
5. Continue observation β Low threat siblings in subnet; maintain baseline monitoring
## Conclusion
IP 20.9.85.55 represents legitimate Microsoft Azure cloud infrastructure with no active threat indicators. The Moderate Risk score (65) reflects cloud infrastructure classification and DNSBL listings rather than malicious activity. SOC teams should treat this as benign cloud traffic and maintain standard monitoring without additional blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.0.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-31 13:32:08 UTC |
| Last Seen | 2026-08-13 01:37:46 UTC |
| Profile Built | 2026-08-13 01:49:17 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.