IP address 52.123.249.15/32 was identified as Microsoft Corporation infrastructure (AS8075) located in Redmond, WA. The system operated as a cloud compute host with active services on ports 80, 443, and 8443. TLS certificate validation confirmed association with outlook.com and Microsoft Corporation domains.
The asset maintained a Low Risk reputation with a risk score of 25. No threat indicators, known campaigns, or spam activity were detected during the observation period. Behavioral analysis indicated no honeypot hits, enumeration strikes, or WAF violations. However, data analysis revealed a contradiction between the claimed geolocation and RTT physics measurements, specifically noting an RTT of 69.0ms against a theoretical minimum of 154.1ms for the recorded distance. Additionally, one DNSBL listing was recorded.
Due to signal contradictions present in the observation history, the address required monitoring for potential changes. No immediate firewall rules were recommended, but continuous surveillance was advised to validate infrastructure stability.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.120.0.0/14 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 8443 | https-alt | tcp | β |
| Closed Ports | 22, 25, 3389, 8080 (3 open / 7 scanned) | ||
| Server | Microsoft-HTTPAPI/2.0 |
| HTTP Title | β |
π TLS Certificate
| SANs | outlook.com*.hotmail.com*.internal.outlook.com*.live.com*.office.com*.office365.com*.outlook.com*.outlook.office365.comattachment.outlook.live.netattachment.outlook.office.net |
| Valid From | 2026-06-26T00:00:00+00:00 |
| Valid Until | 2027-01-10T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 0E371D2766FD365DADDCF4004297839E |
| Thumbprint | C7C19E04464D744D810EF31A24C54FC22A7909C5 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-20 00:42:24 UTC |
| Last Seen | 2026-09-20 00:42:24 UTC |
| Profile Built | 2026-09-23 06:18:59 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.