# IP Intelligence Briefing: 51.104.61.179/32
Classification: Microsoft Azure Cloud Infrastructure | Risk Level: Moderate (50/100)
## Executive Summary
IP 51.104.61.179 is identified as Microsoft Azure cloud infrastructure with moderate risk characteristics. The IP operates within the 51.104.0.0/16 CIDR block, registered under ASN 8075 (Microsoft Corporation). Open Remote Desktop Protocol (RDP) port 3389 represents a potential attack surface requiring monitoring.
## Infrastructure Profile
- Organization: Divya Quamara
- ASN: 8075 (Microsoft Azure)
- Network Block: 51.104.0.0/16
- Geolocation: Cardiff, Wales, GB (51.4801, -3.1855)
- Infrastructure Type: Cloud Provider (Azure)
- Network Role: Single-Service Host
## Threat Indicators Assessment
- Risk Score: 50 (Moderate)
- Abuse Confidence: Not flagged
- Blacklist Status: 0/0 lists
- Known Campaigns: None detected
- Tor Exit: No
- Spam Source: No
- Known Attacker: No
DNSBL Status: Listed on 2 of 8 DNSBLs (dnsblListedCount: 2, dnsblTotalLists: 8)
## Service Exposure
- Open Ports: TCP/3389 (RDP)
- TLS Certificate: None detected
- HTTP Title: None detected
- Email Authentication: No SPF/DMARC records present
## Neighborhood Analysis
The /24 subnet (51.104.61.0.0/24) shows:
- Abuse Density: 0%
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Risk Distribution: No high/medium/low risk neighbors detected in the immediate neighborhood
## Relationship Graph
Four detected relationships, all classified as "Same Network" with target value "cloud", indicating Azure cloud infrastructure associations.
## Historical Observations
Total Signals: 16 observations
Most Recent: 2026-08-06 09:02:26 UTC
Key Historical Signals:
- Abuse Density: 1 (2026-08-06)
- Subnet Classification: mostly_clean
- Inherited Risk: 2
- Geolocation Validation: Plausible (distance: 679.8km)
- ICMP: Blocked (unable to validate)
- Ownership: ARIN registration confirmed
Threat Persistence: 0 days observed
Is Persistently Malicious: No
## Control Plane Data
- BGP Prefix: 51.104.0.0/15
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- RPKI State: Not applicable
- IRR Consistency: Not applicable
## Recommended Security Actions
Based on the risk profile and open RDP port exposure:
1. Rate Limit RDP Access: Implement rate limiting on TCP/3389 to prevent brute force attacks
2. Monitor DNSBL Listings: Investigate the 2 DNSBL listings for potential reputation impact
3. Azure Service Monitoring: Correlate with Microsoft Azure security events for the 51.104.0.0/16 block
4. Geo-Location Verification: Validate claimed Cardiff location against actual traffic patterns
## Analyst Notes
This IP operates within legitimate Microsoft Azure cloud infrastructure. The moderate risk score (50) is driven primarily by DNSBL listings and the open RDP port. No active malicious indicators detected. The single threat observation recorded in historical data did not result in persistent malicious classification. SOC teams should monitor RDP port activity but can expect this to be cloud infrastructure rather than an attack vector.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | cloud |
| CIDR Block | 51.104.0.0/16 |
| RIR | ARIN |
| Country | EU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 29% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-06 06:40:41 UTC |
| Last Seen | 2026-08-13 08:50:18 UTC |
| Profile Built | 2026-08-13 09:30:57 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.