IP address 52.112.53.65 was identified as Microsoft Corporation infrastructure (ASN 8075) within the Microsoft Azure cloud. Geolocation data placed the host in Phoenix, AZ. The reputation profile indicated a Low Risk status with a score of 25. No malicious indicators were detected, and the address was not listed on any blacklists.
Technical reconnaissance confirmed active services on ports 80 and 443. TLS certificate analysis showed issuance by Microsoft TLS G2 RSA CA OCSP 02 for *.trouter.teams.microsoft.com. HTTP/2.0 traffic was recorded with a 200 status code and HSTS headers enabled.
Neighborhood analysis classified the subnet as clean with an abuse density of 0.0294. One sibling IP was flagged as a threat among 34 active neighbors. The overall confidence label was Very Low. The recommendation was to Monitor the address due to the clean neighborhood classification and low risk profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.96.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.trouter.teams.microsoft.com*.trouter.communication.microsoft.com*.trouter.communications.svc.cloud.microsoft |
| Valid From | 2026-08-28T00:38:09+00:00 |
| Valid Until | 2027-02-24T00:38:09+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384RSA |
| Validity Period | 180 days |
| Serial Number | 4100CC858A890505E819966FD0000000CC858A |
| Thumbprint | A6CF58214B154246E2CB1570D72490712C8951EA |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 25% | 1 | 1 |
| Overall | 27% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-21 12:23:23 UTC |
| Last Seen | 2026-09-25 10:07:56 UTC |
| Profile Built | 2026-09-25 10:32:09 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 34 |
Full dossier details are available via our API.