# IP Intelligence Briefing: 207.46.224.80/32
Classification: Moderate Risk (Score: 50/100)
Date: Analysis based on observation data through 2026-08-06
---
## Executive Summary
IP address 207.46.224.80 is a Microsoft Azure cloud infrastructure endpoint with moderate risk classification. The IP belongs to Microsoft Corporation (ASN 8075, MICROSOFT-GLOBAL-NET) and is geolocated to Singapore. No active threat indicators, open ports, or service banners were detected. The IP is classified as cloud compute infrastructure with firewall/no services designation.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate Risk) |
| **Organization** | Microsoft Corporation |
| **ASN** | 8075 |
| **Network Block** | 207.46.0.0/16 |
| **Geolocation** | Singapore (SG) |
| **Infrastructure Type** | CloudCompute (Microsoft Azure) |
| **Open Ports** | None detected |
| **DNS Resolution** | None detected |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 2 of 8 lists |
## Neighborhood Analysis (207.46.224.0/24)
The IP resides in a subnet with 5 sibling addresses showing the following risk distribution:
- High Risk: 0 IPs
- Medium Risk: 2 IPs
- Low Risk: 3 IPs
Neighboring IP risk scores range from 25-50, with one sibling (207.46.224.91) matching the subject IP's risk score of 50. Subnet abuse density is 0.1667, indicating minimal malicious activity in the immediate neighborhood.
## Observation History
Sixteen observations were recorded. Key signals include:
- Subnet classification: "mostly_clean" with inherited risk of 2
- Geo validation: ICMP blocked; geolocation validation attempted but inconclusive
- No persistent malicious behavior detected (threat persistence: 0 days)
- No correlated campaigns or certificate matches observed
## Relationships
Six relationship entries identified, all classified as "Same Network" pointing to MICROSOFT-GLOBAL-NET. No external relationships detected to hostnames, organizations, certificates, or other IP entities.
## Threat Indicators
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not available
## Recommended Security Actions
The IP carries a moderate risk score of 50. Recommended firewall rules for blocking:
```
iptables: iptables -A INPUT -s 207.46.224.80 -j DROP
nftables: nft add rule inet filter input ip saddr 207.46.224.80 drop
nginx: deny 207.46.224.80;
Cloudflare WAF: Block IP 207.46.224.80
AWS WAF: 207.46.224.80/32
```
Security Assessment: This IP is Microsoft Azure cloud infrastructure with no detected active services. The moderate risk score reflects the IP's presence in a shared cloud environment rather than malicious activity. Blocking is recommended as a precautionary measure, though false positive potential exists given the IP's legitimate Microsoft ownership and clean neighborhood profile. Monitor for any changes in behavior or emergence of open ports.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MICROSOFT-GLOBAL-NET |
| CIDR Block | 207.46.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-02 17:02:22 UTC |
| Last Seen | 2026-08-13 03:49:09 UTC |
| Profile Built | 2026-08-13 04:12:51 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.