# IP Intelligence Briefing: 20.91.226.158/32
Classification: Low Risk | Risk Score: 25/100 | Status: Monitored
## Overview
The target IP address 20.91.226.158 is identified as Microsoft Azure cloud infrastructure belonging to ASN 8075 (Microsoft Corporation). The IP is geolocated to Stockholm, Sweden (AB region) and operates within the 20.33.0.0/16 CIDR block. Current reputation status is Low Risk with no active threat indicators.
## Technical Profile
- Organization: Microsoft Corporation (MSFT)
- Network: 20.33.0.0/16 | ASN: 8075
- RIR: ARIN | Classification: CloudCompute (Microsoft Azure)
- Infrastructure Type: Cloud Hosting
- Geolocation: Stockholm, SE (59.33°N, 18.07°E)
- Timezone: Europe/Stockholm
## Network Services & Ports
No open ports or active services detected on the IP address. DNS resolution shows no PTR hostnames or forward-confirmed reverse DNS records. No TLS certificates, HTTP titles, or service banners were observed during scanning.
## Threat Indicators
- Blacklist Count: 0
- Threat Feeds: None
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not applicable
## Neighborhood Analysis
The /24 subnet (20.91.226.158/24) shows zero abuse density and is classified as clean. No neighboring IPs with threat indicators were identified. Total sibling count: 1 active IP in the subnet.
## Historical Observations
Fifteen observations recorded as of 2026-08-06. The IP has demonstrated consistent behavior:
- Persistent cloud infrastructure classification (Microsoft Azure)
- Stable geolocation to Stockholm region
- No changes in threat posture or ownership
- Zero threat observation count
- No persistent malicious activity detected
## Control Plane
- BGP Prefix: 20.64.0.0/10
- RPKI State: Not evaluated
- Route Stability: Unstable (route changes observed)
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
## Relationships
Three relationships identified, all pointing to Microsoft (MSFT) network infrastructure. No external organizational, hostname, or certificate relationships detected.
## Recommended Actions
No automated security actions recommended based on current risk profile. The IP is classified as legitimate cloud infrastructure with no threat indicators.
## Intelligence Summary
20.91.226.158 is a Microsoft Azure cloud compute IP address with low risk characteristics. The IP shows no signs of malicious activity, is not blacklisted, and belongs to a clean neighborhood. SOC teams should treat this IP as legitimate Microsoft infrastructure. No immediate blocking or mitigation actions required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.33.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 28% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-03 17:30:35 UTC |
| Last Seen | 2026-08-13 05:15:06 UTC |
| Profile Built | 2026-08-13 05:26:22 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.