Target: 52.108.42.38/32
Classification: Microsoft Azure Infrastructure
Risk Assessment: Low Risk (Score: 25)
Intelligence Summary:
Target IP 52.108.42.38 was identified as Microsoft Azure infrastructure owned by Microsoft Corporation (ASN 8075). While the overall risk score remained low at 25, the profile data was classified as contradictory with a coherence score of 48. Geolocation analysis claimed Toronto, Canada, yet RTT measurements recorded 31ms, violating the minimum physical latency of 121.6ms for that distance. Additional inconsistencies included geo-source disagreements between Canada and the United States, and a TLS certificate subject claiming US location versus primary geo data citing Canada. Despite no active threat indicators or known campaign affiliations, one DNSBL listing was observed among eight total lists. The system recommended rate-limiting traffic due to multiple signal contradictions and an unreliable profile. The target served HTTPS traffic on port 443 via Microsoft-IIS/10.0 associated with the officeapps.live.com domain.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.96.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 4/6 domains |
| DMARC | 6/6 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 6 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Microsoft-IIS/10.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | officeapps.live.comofficeppe.live.com*.office.live.comoffice.live.com*.officeapps.live.comofficeapps-df.live.com*.officeapps-df.live.com*.online.office.com*.online.office365.comonline.office.com |
| Valid From | 2026-06-19T16:30:14+00:00 |
| Valid Until | 2026-12-16T16:30:14+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384RSA |
| Validity Period | 180 days |
| Serial Number | 5500CD90EA69DAA9CB8E3DC930000000CD90EA |
| Thumbprint | CFEF1CCA6024573835F57749AA3E74D9F3ADE8BA |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 7 |
| routing | 30% | 3 | 4 |
| services | 36% | 2 | 7 |
| ownership | 27% | 2 | 4 |
| reputation | 27% | 1 | 5 |
| geolocation | 37% | 2 | 6 |
| Overall | 33% | 12 | 33 |
| Data Coherence | Contradictory (48%) โ 3 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: CA, US
โ TLS certificate claims US but primary geo says CA
๐ Observation Timeline ๐ Live
| First Seen | 2026-09-06 09:41:03 UTC |
| Last Seen | 2026-09-27 03:15:20 UTC |
| Profile Built | 2026-09-27 03:19:41 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 55 |
Full dossier details are available via our API.