Intelligence analysis identified 52.123.244.227 as Microsoft Corporation cloud infrastructure (ASN 8075) within the 52.120.0.0/14 block, operating TLS certificates for Outlook.com. While the asset maintained a Low Risk reputation score of 25, threat actor categorization labeled the host as "Suspicious" due to the presence of threat indicators without specific campaign attribution.
Observations recorded activity between September 11 and September 19, 2026. Technical validation revealed data inconsistencies, including geolocation discrepancies between the United States and Brazil, alongside an RTT physics violation (127ms observed against 197.1ms minimum possible). The address appeared on one of eight monitored DNSBLs. While the immediate neighborhood (52.123.244.227/24) remained mostly clean with an abuse density of 0.14, seven sibling IPs within the subnet were flagged as threats.
Operational recommendation is to Monitor the address. The profile exhibited mixed signal coherence (score 60) and low confidence (0.3083), necessitating observation for changes in behavior or ownership status.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.120.0.0/14 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 5/7 domains |
| DMARC | 6/7 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 7 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 8443 | https-alt | tcp | β |
| Closed Ports | 22, 25, 3389, 8080 (3 open / 7 scanned) | ||
| Server | Microsoft-HTTPAPI/2.0 |
| HTTP Title | β |
π TLS Certificate
| SANs | outlook.com*.hotmail.com*.internal.outlook.com*.live.com*.office.com*.office365.com*.outlook.com*.outlook.office365.comattachment.outlook.live.netattachment.outlook.office.net |
| Valid From | 2026-06-26T00:00:00+00:00 |
| Valid Until | 2027-01-10T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 0E371D2766FD365DADDCF4004297839E |
| Thumbprint | C7C19E04464D744D810EF31A24C54FC22A7909C5 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 33% | 2 | 4 |
| ownership | 33% | 2 | 4 |
| reputation | 31% | 1 | 4 |
| geolocation | 33% | 2 | 4 |
| Overall | 31% | 10 | 22 |
| Data Coherence | Mixed Signals (60%) β 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β Geo sources disagree on country: BR, US
π Observation Timeline π Live
| First Seen | 2026-09-11 13:24:51 UTC |
| Last Seen | 2026-09-19 16:44:56 UTC |
| Profile Built | 2026-09-19 17:02:57 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 39 |
Full dossier details are available via our API.