Intelligence assessment of IP address 40.116.110.236/32 identified the asset as legitimate Microsoft Azure infrastructure. Ownership records linked the address to Microsoft Corporation (ASN 8075) with a registration in the US. Geolocation data placed the endpoint in Boston, US, while network role classification identified the host as a cloud compute web server.
Traffic analysis confirmed the host opened ports 80 and 443 for HTTP and HTTPS. Server banners reported Microsoft-IIS/10.0, and a TLS certificate was issued by Microsoft TLS G2 RSA CA OCSP 02 for arc.msn.com. Behavioral analysis recorded zero enumeration strikes, no honeypot hits, and no associated malicious campaigns. The address maintained a risk score of zero and appeared on no known blacklists or threat feeds.
Based on the clean reputation and lack of threat indicators, the recommended action was to allow traffic with an information-level severity rating.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 40.74.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 2/3 domains |
| DMARC | 2/3 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 3 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Microsoft-IIS/10.0 |
| HTTP Title | β |
π TLS Certificate
| SANs | dynmsg.modpim.comdynmsgrest.modpim.comarcproxy.microsoft.comarc-west.msn.comarc-east.msn.comarc-emea.msn.comarc-apac.msn.comfd.api.iris.microsoft.comfd-emea.api.iris.microsoft.comfd.api.orgmsg.microsoft.com |
| Valid From | 2026-08-11T20:53:55+00:00 |
| Valid Until | 2027-02-07T20:53:55+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384RSA |
| Validity Period | 180 days |
| Serial Number | 4100D4CFB2921A1CFB0079EBBA000000D4CFB2 |
| Thumbprint | 13BC0C4361AED6012BBFA4D16B0403F317B62380 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 49% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 33% | 2 | 4 |
| ownership | 27% | 2 | 3 |
| reputation | 19% | 1 | 2 |
| geolocation | 27% | 2 | 2 |
| Overall | 28% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-13 10:08:33 UTC |
| Last Seen | 2026-09-20 22:26:19 UTC |
| Profile Built | 2026-09-20 22:38:01 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 34 |
Full dossier details are available via our API.