IP INTELLIGENCE BRIEFING: 52.165.58.32/32
Classification: Low-Risk Cloud Infrastructure IP | Microsoft Azure | Risk Score: 25
Asset Profile:
- Organization: Microsoft Corporation (ASN 8075)
- Network: MSFT | CIDR Block: 52.145.0.0/16
- Infrastructure Type: Microsoft Azure CloudCompute
- Geolocation: Des Moines, Iowa, US
- Control Plane: Route unstable (isRouteStable: false)
Threat Assessment:
The IP presents a low-risk profile with no active threat indicators. No known attacker campaigns, spam sources, or Tor exit node activity detected. Blacklist presence is minimal (1 of 8 DNSBL listings). The IP operates as firewalled cloud infrastructure with no detectable open ports or active services.
Historical Observations:
22 signal observations recorded. Geolocation consistently reports Des Moines, Iowa. Recent activity includes multiple blacklist listings detected in August 2026. The IP demonstrates persistent ownership to Microsoft Corporation with no ownership changes.
Subnet Analysis (52.165.58.0/24):
- Abuse Density: 0%
- Classification: Mostly Clean
- Total Siblings: 3 | Active: 3
- Risk Distribution: 2 low-risk, 0 medium/high-risk
- Neighbor IPs: 52.165.58.34 (Risk: 25), 52.165.58.39 (Risk: 25)
- Inherited Risk: 5
Relationship Network:
12 relationship entries identified, all mapped to Microsoft (MSFT) network infrastructure. Indicates consistent Microsoft Azure cloud allocation.
Recommendations:
- Monitor: Maintain monitoring due to 1 DNSBL listing. Investigate source of listing if not expected.
- Block: No blocking required. Low-risk score of 25 with Microsoft Azure infrastructure.
- Allow: Permitted inbound/outbound traffic based on organizational security policies.
- Context: This is legitimate cloud infrastructure. Do not mistake for malicious activity.
SOC Analyst Notes:
This IP represents Microsoft Azure cloud compute infrastructure. The single DNSBL listing warrants investigation to determine cause, but the low risk score (25), clean neighborhood profile, and consistent Microsoft ownership indicate this is operational cloud infrastructure, not malicious activity. Standard cloud traffic policies apply. No immediate threat response actions required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.145.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 21% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 08:45:46 UTC |
| Last Seen | 2026-08-12 19:37:58 UTC |
| Profile Built | 2026-08-12 19:53:21 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.