IP Intelligence Briefing: 207.46.13.64
Date: 2026-06-12
---
**1. IP Profile**
- Risk Score: 25 (Low Risk)
- Provider: Microsoft Corporation (AS8075)
- Geolocation: Madison, WI, US (Bingbot infrastructure)
- Network Role: CloudCompute (Microsoft)
- Threat Indicators: No active threats detected.
- DNS: Associated with `msnbot-207-46-13-64.search.msn.com` (Microsoft-owned).
Key Findings:
- The IP is part of Microsoft's global network (`MICROSOFT-GLOBAL-NET`) and is associated with Bingbot, likely a crawler or indexing bot.
- No open ports or TLS certificates detected, suggesting a server or infrastructure asset.
- Historical data shows low risk, but one observation flagged "has_threats" with 20 pulses (potential false positives or outdated data).
---
**2. Observation History**
- Recent Activity (2026-06-12):
- Low Risk: Consistent with Microsoft's infrastructure.
- Threat Signals: One observation (confidence 0.95) indicated "has_threats" with 20 pulses, but no current indicators.
- Geolocation: Plausible in Madison, WI, but no RTT or probe data.
- Network Stability: Route stability score is 0 (unstable), but Microsoft's infrastructure is generally reliable.
Recommendation: Monitor for anomalies in threat signals or unexpected geolocation changes.
---
**3. Relationships**
- Linked Entities:
- Microsoft Corporation (AS8075)
- DNS: `msnbot-207-46-13-64.search.msn.com` (Microsoft domain)
- Subnet: `207.46.13.64/24` (mixed classification, 0.22 abuse density).
Key Findings:
- Strong ties to Microsoft's infrastructure.
- No connections to known malicious organizations or campaigns.
- DNS records are valid and consistent with Microsoft's domain.
---
**4. Neighborhood Analysis**
- Subnet: `207.46.13.64/24`
- Abuse Density: 0 (low risk).
- Neighbors:
- 30 IPs in subnet, most with low risk (25/30).
- 6 IPs flagged as "threat siblings" (riskScore β₯25).
Key Findings:
- Subnet is mixed but primarily low-risk.
- No immediate threats in the neighborhood, but 6 IPs have higher risk scores.
---
**5. Actionable Intelligence**
- SOC Analyst Notes:
- The IP is likely a legitimate Microsoft asset (Bingbot crawler).
- Historical threats may be false positives or outdated data.
- Monitor subnet activity for unusual traffic or new threat indicators.
- No immediate mitigation required, but ensure alignment with Microsoft's network behavior.
Next Steps:
- Cross-check with Microsoft's internal systems to confirm the IP's role.
- Continuously monitor for changes in threat signals or geolocation.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MICROSOFT-GLOBAL-NET |
| CIDR Block | 207.46.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | msnbot-207-46-13-64.search.msn.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | msnbot-207-46-13-64.search.msn.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 19% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 10:58:51 UTC |
| Last Seen | 2026-06-29 07:40:00 UTC |
| Profile Built | 2026-06-29 07:44:00 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.