Analysis of 52.111.251.22/32 identified the address within Microsoft Azure infrastructure (ASN 8075, MSFT). Ownership records confirmed the asset belonged to Microsoft Corporation. The host operated HTTP and HTTPS services with a TLS certificate issued by Microsoft TLS G2 RSA CA OCSP 02 for the subject augloop.office.com.
The profile displayed a Low Risk reputation (Score 25) but contained significant data contradictions. Geolocation sources disagreed on the country (CA vs US), and the claimed Toronto location contradicted RTT physics measurements indicating a distance of 6078km. The TLS certificate subject claimed US jurisdiction while primary geo data indicated Canada.
No known campaigns or blacklist listings were associated with the IP, and no specific attacker indicators were observed. Despite the absence of confirmed malicious activity, the host was classified as a Suspicious Host due to signal inconsistencies. Security operations recommended rate-limiting traffic due to the unreliable profile and multiple signal contradictions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.96.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 2/4 domains |
| DMARC | 4/4 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 4 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Kestrel |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | augloop.office.com*.augloop.office.comaugloop.svc.cloud.microsoft*.augloop.svc.cloud.microsoftaugloop-msit.office.com*.augloop-msit.office.commsit.augloop.svc.cloud.microsoft*.msit.augloop.svc.cloud.microsoft |
| Valid From | 2026-08-28T14:49:09+00:00 |
| Valid Until | 2027-02-24T14:49:09+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384RSA |
| Validity Period | 180 days |
| Serial Number | 4100D210B9FF08A408B2050550000000D210B9 |
| Thumbprint | 95FB63B6DCA0F798F68A6CD21E3123AF5E7E6F04 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 33% | 2 | 4 |
| ownership | 27% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 38% | 2 | 5 |
| Overall | 29% | 10 | 21 |
| Data Coherence | Contradictory (48%) โ 3 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: CA, US
โ TLS certificate claims US but primary geo says CA
๐ Observation Timeline ๐ Live
| First Seen | 2026-09-01 10:14:17 UTC |
| Last Seen | 2026-09-21 02:21:53 UTC |
| Profile Built | 2026-09-21 02:27:47 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 39 |
Full dossier details are available via our API.