IPDebrief

23.101.2.35

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 23.101.2.35/32

Classification: Microsoft Azure Cloud Infrastructure | Risk Score: 50 (Moderate)

## Ownership and Infrastructure

The IP address 23.101.2.35 belongs to Microsoft Corporation (ASN 8075), registered under CIDR block 23.96.0.0/13. The IP is classified as Microsoft Azure CloudCompute infrastructure with hosting capabilities. The network role indicates firewalled/no services deployment, with no open ports detected.

## Geolocation Signals

Geolocation data presents conflicting signals:

The geographic discrepancy is consistent with Microsoft's global Azure cloud infrastructure and anycast routing patterns.

## Threat Assessment

The IP exhibits minimal threat indicators:

The neighborhood subnet 23.101.2.35/24 shows clean classification with zero abuse density and no adjacent threat siblings.

## Risk History

Fourteen historical observations were retrieved. Ownership remains stable with no changes recorded. The IP is not flagged as persistently malicious. Operator scores indicate minimal concern.

## Recommended Actions

Despite the moderate risk score of 50, the IP is legitimate Microsoft Azure infrastructure. However, if blocking is required based on specific observed behavior:

```

iptables -A INPUT -s 23.101.2.35 -j DROP

nft add rule inet filter input ip saddr 23.101.2.35 drop

Cloudflare WAF: Block IP with expression: ip.src eq 23.101.2.35

```

## Analysis Notes

The moderate risk score (50) may reflect the IP's hosting infrastructure classification rather than malicious activity. The IP shows stable ownership, no known campaigns, and clean adjacent subnet activity. SOC teams should evaluate whether blocking aligns with observed traffic anomalies rather than risk score alone.

Final Assessment: Legitimate Microsoft Azure infrastructure with moderate classification risk. No evidence of active malicious activity.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ญ๐Ÿ‡ฐ Hong Kong
Regionโ€”
CityHong Kong
Timezoneโ€”
Latitude22.28
Longitude114.18

๐Ÿข Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network NameMSFT
CIDR Block23.96.0.0/13
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
13%
12
geolocation
13%
11
Overall19%912
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: HK, US

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-08-11 17:58:48 UTC
Last Seen2026-08-31 17:18:14 UTC
Profile Built2026-08-29 03:38:57 UTC
Data FreshnessLive
Signal Types18
Total Observations21
๐Ÿ” 18 signal types ยท 21 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.