# IP Intelligence Briefing: 20.98.113.13/32
## Executive Summary
IP 20.98.113.13 is Microsoft Azure cloud infrastructure with a low-risk profile. The address belongs to Microsoft Corporation (AS8075) and operates within the 20.33.0.0/16 CIDR block. No active threat indicators or malicious behavior were observed during the intelligence collection period.
## Risk Assessment
- Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Abuse Confidence Score: Null
## Ownership & Infrastructure
- Organization: Microsoft Corporation
- Autonomous System: AS8075 (MSFT)
- Network Name: MSFT
- CIDR Block: 20.33.0.0/16
- Registry: ARIN
- Network Role: Microsoft Azure Cloud Compute
- Classification: Cloud Infrastructure (isCloud: true)
## Geolocation Data
- Country: United States (US)
- Region: Washington (WA)
- City: Quincy
- Coordinates: 47.23° N, -119.85° W
- Timezone: America/Los_Angeles
- GeoValidation: Geolocation plausible, ICMP validation blocked
## Network Services Analysis
- Open Ports: None detected
- TLS Certificate: Not configured
- HTTP Title: Not available
- Server Banner: None
- Hosted Domains: 0
- DNS PTR Records: None
- DNSBL Status: Listed on 1 of 8 threat feeds
## Threat Indicators
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Known Campaigns: None
- Threat Feeds: Empty
- Blacklist Count: 0
- Pulsedive Risk: Null
## Historical Observations
The IP has been observed 22 times across multiple signal types since 2026-06-16. Signal classifications indicate:
- Routing: Minimal operator score (0.1304)
- Services: No open ports or services exposed
- Ownership: Consistent with Microsoft infrastructure
- Reputation: Stable low-risk classification
- Subnet Classification: "mostly_clean" with inherited risk level 2
No persistent malicious behavior detected. Threat observation count: 1.
## Neighborhood Analysis (20.98.113.0/24)
- Abuse Density: 0
- Active Siblings: 0
- Total Siblings: 1
- Threat Siblings: 1 (historical)
- Risk Distribution: No high/medium/low risk neighbors detected
- Subnet Classification: Mostly clean
## Relationship Graph
- Total Relationships: 8
- Relationship Types: Same Network (MSFT)
- External Connections: None to other organizations, hostnames, or certificates
## Recommended Actions
Based on the low-risk profile and Microsoft Azure classification:
- Default Action: Allow traffic with standard monitoring
- Firewall Rules: No blocking required; maintain baseline logging
- WAF/IPS Rules: No specific rules recommended
- Investigation Priority: Low
## Threat Intelligence Narrative
20.98.113.13 operates as Microsoft Azure cloud infrastructure within the legitimate Microsoft network range. The IP demonstrates clean historical behavior with no evidence of command-and-control, scanning, or exploitation activity. Network classification confirms cloud compute purpose with no exposed services. The subnet exhibits minimal abuse density, and the IP shows no correlation with known threat campaigns or malicious actors. SOC analysts may treat this address as trusted infrastructure requiring only standard operational monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.33.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-06 07:27:23 UTC |
| Last Seen | 2026-06-21 12:56:45 UTC |
| Profile Built | 2026-06-21 13:06:33 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.