Intelligence Briefing: 52.112.53.60
The IP address 52.112.53.60 was identified as a Microsoft Azure cloud compute instance operated by Microsoft Corporation (ASN 8075). Ownership records indicated the address belonged to the MSFT organization within the 52.96.0.0/12 CIDR block.
Risk assessment classified the address as Low Risk with a risk score of 20. No indicators of compromise were found, including zero blacklist entries and no association with known attacker campaigns. The address served web traffic via HTTP and HTTPS on ports 80 and 443. TLS certificates linked the address to Microsoft Teams router domains.
Operational analysis revealed a contradiction between claimed geolocation (Phoenix, AZ) and measured Round Trip Time physics, which marked the data as physically implausible. Despite this inconsistency, the neighborhood classification remained clean with no threat siblings detected.
The recommendation was to monitor the address due to the presence of signal contradictions, while maintaining a low severity stance given the legitimate cloud infrastructure profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.96.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.trouter.teams.microsoft.com*.trouter.communication.microsoft.com*.trouter.communications.svc.cloud.microsoft |
| Valid From | 2026-08-28T00:38:09+00:00 |
| Valid Until | 2027-02-24T00:38:09+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384RSA |
| Validity Period | 180 days |
| Serial Number | 4100CC858A890505E819966FD0000000CC858A |
| Thumbprint | A6CF58214B154246E2CB1570D72490712C8951EA |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 33% | 2 | 4 |
| ownership | 27% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 2 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-04 10:12:25 UTC |
| Last Seen | 2026-09-14 19:51:37 UTC |
| Profile Built | 2026-09-14 20:00:35 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 34 |
Full dossier details are available via our API.