Intelligence analysis of IP 40.99.236.98/32 identified the address as a Microsoft Corporation infrastructure endpoint. Ownership records attributed the address to ASN 8075 (MSFT) within the ARIN region, with geolocation data locating the server in Redmond, WA, US. The address operated as a CloudCompute Web Server, exposing ports 80 and 443. Server fingerprinting returned a Microsoft-HTTPAPI/2.0 banner, and TLS inspection confirmed certificates issued by DigiCert Inc validating subjects under outlook.com and associated Microsoft domains.
Threat assessment assigned a Low Risk classification with a risk score of 25. No indicators linked to known campaigns or malicious actor profiles were detected; however, the address is tagged as a Suspicious Host. Network neighborhood data revealed an abuse density of 0.5 and two threat siblings within the /24 subnet. A contradiction exists between the claimed geolocation and RTT physics measurements, which recorded a 30ms latency inconsistent with a 5365km distance. Overall data confidence remained Very Low (0.225).
Operational recommendations advised monitoring the asset due to signal contradictions and insufficient data to classify intent. The address remained active between 2026-09-04 and 2026-09-20.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 40.74.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 10/14 domains |
| DMARC | 12/14 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 14 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Microsoft-HTTPAPI/2.0 |
| HTTP Title | β |
π TLS Certificate
| SANs | outlook.com*.hotmail.com*.internal.outlook.com*.live.com*.office.com*.office365.com*.outlook.com*.outlook.office365.comattachment.outlook.live.netattachment.outlook.office.net |
| Valid From | 2026-06-26T00:00:00+00:00 |
| Valid Until | 2027-01-10T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 0E371D2766FD365DADDCF4004297839E |
| Thumbprint | C7C19E04464D744D810EF31A24C54FC22A7909C5 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 6 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 4 |
| ownership | 27% | 2 | 4 |
| reputation | 27% | 1 | 5 |
| geolocation | 33% | 2 | 5 |
| Overall | 27% | 10 | 25 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-04 01:21:27 UTC |
| Last Seen | 2026-09-20 23:59:24 UTC |
| Profile Built | 2026-09-21 00:10:57 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 57 |
Full dossier details are available via our API.