# IP Intelligence Briefing: 52.136.139.46/32
## Executive Summary
IP address 52.136.139.46 is an active Microsoft Azure cloud infrastructure endpoint classified as Low Risk with an overall risk score of 25. The asset operates within the Microsoft Corporation network (ASN 8075) and demonstrates stable cloud compute characteristics with no persistent malicious activity indicators.
## Ownership and Network Classification
- Organization: Microsoft Corporation
- AS Number: 8075 (MSFT)
- CIDR Block: 52.132.0.0/14
- Network Role: Microsoft Azure Cloud Compute Infrastructure
- Geolocation: United States (PAC region), Marseille coordinates
- DNS Classification: Cloud Hosting (isHosting: true), Cloud Provider (isCloud: true)
## Risk Assessment
- Overall Risk Score: 25/100 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Abuse Confidence: No active threat indicators detected
- Known Campaigns: None identified
- Blacklist Status: Listed on 1 of 8 DNS blacklists (dnsblListedCount: 1)
## Service and Port Analysis
- Open Ports: None detected
- HTTP/TLS Services: No active web services or TLS certificates
- DNS Records: No PTR hostnames, no forward resolution
- Email Authentication: No SPF or DMARC records configured
## Neighborhood Analysis
- Subnet: 52.136.139.46/24
- Abuse Density: 1 (minimal)
- Classification: Mostly Clean
- Threat Siblings: 1 identified in /24 range
- Inherited Risk: 2
- Active Siblings: 1
## Historical Observation Data
Analysis of 19 observations indicates:
- Latest Observation: 2026-06-16T01:03:43 UTC
- Threat Persistence: 0 days
- Ownership Changes: 0
- Campaign Likelihood: None
- Behavioral Indicators: No honeypot hits, enumeration strikes, or WAF violations detected
## Related Entities
Nine network-level relationships identified, all associated with Microsoft Corporation (MSFT) network infrastructure. No hostname, certificate, or organizational entity relationships detected beyond the network scope.
## Recommended Actions
Based on current risk profile, no immediate defensive actions are required. The IP operates within legitimate Microsoft Azure infrastructure with no active threat indicators. Standard monitoring is recommended.
## Analyst Notes
While the IP is classified as low-risk Microsoft cloud infrastructure, the presence of DNS blacklist entries warrants continued monitoring. The subnet contains one identified threat sibling, suggesting localized risk within the /24 range. The absence of open ports and services indicates this endpoint may be dormant or internal-facing infrastructure.
---
*Intelligence compiled from IPDebrief platform data. For SOC integration, correlate with internal traffic logs and threat intelligence feeds for enhanced situational awareness.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.132.0.0/14 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-26 06:51:28 UTC |
| Last Seen | 2026-06-29 02:54:56 UTC |
| Profile Built | 2026-06-29 08:58:41 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.