Subject: Intelligence Briefing for IP 52.110.1.169/32
Ownership and Location
The IP address 52.110.1.169 is registered to Microsoft Corporation (ASN 8075) within the 52.96.0.0/12 block. Geolocation data associated the host with Redmond, Washington, United States. However, RTT physics measurements indicated a distance of approximately 7066km, creating a contradiction with the claimed US location.
Network Role and Services
Analysis classified the infrastructure as a cloud compute web server and hosting provider. Active services were observed on ports 80 (HTTP) and 443 (HTTPS). TLS certificate validation confirmed the subject as Microsoft Corporation for outlook.com and associated domains. The server banner reported Microsoft-HTTPAPI/2.0.
Threat Assessment
The overall reputation score was recorded as Low Risk (Score: 25). No specific threat indicators, known campaigns, or blacklist listings were detected. Behavioral metrics showed zero honeypot hits, enumeration strikes, or WAF violations. Despite the low risk score, the host was tagged as a Suspicious Host within the network neighborhood.
Recommendations
The profile indicated a Low Severity risk with a recommendation to Monitor. The decision was based on signal contradictions present between geolocation and RTT data, alongside a low overall confidence score (0.1667). Current intelligence suggests no immediate threat, but observation is required due to data inconsistencies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.96.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 10/14 domains |
| DMARC | 12/14 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 14 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Microsoft-HTTPAPI/2.0 |
| HTTP Title | β |
π TLS Certificate
| SANs | outlook.com*.hotmail.com*.internal.outlook.com*.live.com*.office.com*.office365.com*.outlook.com*.outlook.office365.comattachment.outlook.live.netattachment.outlook.office.net |
| Valid From | 2026-06-26T00:00:00+00:00 |
| Valid Until | 2027-01-10T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 0E371D2766FD365DADDCF4004297839E |
| Thumbprint | C7C19E04464D744D810EF31A24C54FC22A7909C5 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 6 |
| routing | 13% | 1 | 1 |
| services | 38% | 2 | 5 |
| ownership | 33% | 2 | 4 |
| reputation | 32% | 1 | 5 |
| geolocation | 37% | 2 | 6 |
| Overall | 32% | 10 | 27 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-07 13:17:28 UTC |
| Last Seen | 2026-09-25 01:24:20 UTC |
| Profile Built | 2026-09-25 01:38:19 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 56 |
Full dossier details are available via our API.