Intelligence assessment identified IP 4.209.250.170/32 as Microsoft Azure cloud infrastructure owned by Microsoft Corporation (AS8075). The asset was located in Dublin, Ireland, though the TLS certificate indicated a United States origin, creating geographic discrepancies. Risk scoring assigned a Low Risk classification (score: 25), while the threat actor classification was "Suspicious Host" with very low confidence (0.25). The host operated on TCP/443 (HTTPS) with a Microsoft-signed certificate. Behavioral analysis showed no active attacks, but the IP appeared on one DNS blacklist list. Due to conflicting signal coherence and mixed validation states, analysts recommended monitoring the host for changes rather than immediate blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 4.208.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | *.tas00.cwsapp.update.microsoft.com*.tas00.cwsapp-prod.dcat.dsp.mp.microsoft.com*.backend.tas00.cwsapp-prod.dcat.dsp.mp.microsoft.comtas00.cwsapp.update.microsoft.com |
| Valid From | 2026-02-03T19:04:25+00:00 |
| Valid Until | 2027-02-03T19:04:25+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 330000029ECD754D8234F074F200000000029E |
| Thumbprint | CB4C46E1029FC04D0EF6C24885AA3F2EF6641D60 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 8 |
| routing | 13% | 1 | 1 |
| services | 33% | 2 | 5 |
| ownership | 27% | 2 | 4 |
| reputation | 27% | 1 | 5 |
| geolocation | 33% | 2 | 6 |
| Overall | 28% | 10 | 29 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims US but primary geo says IE
๐ Observation Timeline ๐ Live
| First Seen | 2026-09-04 06:10:21 UTC |
| Last Seen | 2026-09-26 11:22:40 UTC |
| Profile Built | 2026-09-26 11:33:51 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 51 |
Full dossier details are available via our API.