Intelligence Summary: 52.112.84.213
The IP address 52.112.84.213 was identified as Microsoft Corporation infrastructure (ASN 8075) operating within the Microsoft Azure cloud environment (CIDR: 52.96.0.0/12). Passive monitoring revealed open HTTP (port 80) and HTTPS (port 443) services. TLS certificate analysis associated the host with Microsoft Teams router endpoints (*.trouter.teams.microsoft.com).
Threat intelligence indicators showed a Low Risk reputation with a risk score of 20. No blacklist hits, known campaigns, or malicious behavior were observed. The network neighborhood remained clean with zero threat siblings. However, geolocation data indicated San Antonio, Texas, while RTT physics measurements recorded a contradiction between claimed distance and actual latency (59.0ms vs 167.8ms minimum).
Due to signal contradictions, the asset was classified for monitoring with low severity. No immediate action was required beyond continued observation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.96.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 4/4 domains |
| DMARC | 4/4 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 4 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | *.trouter.teams.microsoft.com*.trouter.communication.microsoft.com*.trouter.communications.svc.cloud.microsoft |
| Valid From | 2026-08-28T12:27:04+00:00 |
| Valid Until | 2027-02-24T12:27:04+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384RSA |
| Validity Period | 180 days |
| Serial Number | 5500C2D8D9BD65E3B70F4FCDED000000C2D8D9 |
| Thumbprint | 5E4E3D2AEB32BB6B214F8484590623D210BE5AEA |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 6 |
| routing | 27% | 2 | 3 |
| services | 33% | 2 | 5 |
| ownership | 27% | 2 | 4 |
| reputation | 27% | 1 | 6 |
| geolocation | 33% | 2 | 5 |
| Overall | 31% | 11 | 29 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-07 17:57:03 UTC |
| Last Seen | 2026-09-26 04:46:09 UTC |
| Profile Built | 2026-09-26 05:02:38 UTC |
| Data Freshness | Live |
| Signal Types | 32 |
| Total Observations | 72 |
Full dossier details are available via our API.