IPDebrief

52.165.63.205

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target IP: 52.165.63.205/32

Classification: Microsoft Azure Cloud Infrastructure

Risk Level: Moderate Risk (Score: 40)

Date Generated: 2026-08-05

---

## EXECUTIVE SUMMARY

IP 52.165.63.205 is a Microsoft Azure cloud compute resource located in Des Moines, Iowa. The IP demonstrates moderate risk primarily driven by DNSBL listings (2 of 8 lists), though no active threat indicators or malicious behavior observed. The /24 neighborhood is classified as clean with zero abuse density, suggesting legitimate enterprise cloud operations.

---

## OWNERSHIP & INFRASTRUCTURE

Organization: Microsoft Corporation

ASN: 8075 (MSFT)

Network Block: 52.145.0.0/16

Infrastructure Type: Cloud Compute (Microsoft Azure)

Geolocation: United States, Iowa, Des Moines (41.88°N, 93.1°W)

Timezone: America/Chicago

---

## THREAT INDICATORS

Current Risk Score: 40/100 (Moderate)

Abuse Confidence: Not reported

Blacklist Status: Listed on 2 of 8 DNSBL feeds (max severity: high)

Known Attacker: No

Spam Source: No

Tor Exit Node: No

Campaign Association: None detected

Threat Feeds: Empty

Known Campaigns: None

---

## NETWORK SERVICES & DNS

Open Ports: None detected

TLS Certificate: None

HTTP Title: None

PTR Resolution: None

Forward DNS: Not confirmed

Email Authentication: SPF/DMARC not configured

Hosted Domains: 0

---

## CONTROL PLANE DATA

BGP Prefix: 52.160.0.0/11

Route Stability: False

RPKI State: Not reported

IRR Consistency: Not reported

Route Changes (30d): 0

DNSSEC Valid: Yes

Operator Score: 0.1304 (Minimal)

DNSBL Listed: Yes (2/8 lists)

---

## HISTORICAL OBSERVATIONS

Total Signals Observed: 17

Observation Period: Recent activity from July–August 2026

Key Historical Signals:

Threat Persistence: None

Ownership Changes: 0

---

## RELATIONSHIP GRAPH

Connected Entities: 5

Relationship Type: Same Network (MSFT)

Network Affiliation: All relationships map to Microsoft (MSFT) infrastructure

---

## NEIGHBORHOOD ANALYSIS

Subnet: 52.165.63.0/24

Abuse Density: 0 (Clean)

Risk Distribution: High: 0, Medium: 0, Low: 0

Active Siblings: 0

Threat Siblings: 0

Total Siblings: 1

---

## SECURITY RECOMMENDATIONS

Action: Monitor but do not block. This is legitimate Microsoft Azure infrastructure.

Recommended Actions:

1. Allow traffic from this IP – Microsoft Azure cloud resource

2. Monitor DNSBL listing sources for context on reputation concerns

3. No firewall rules required for this IP

4. Consider whitelisting for Microsoft cloud traffic if applicable

Risk Context: The moderate risk score (40) is primarily driven by DNSBL listings rather than active malicious behavior. The clean /24 neighborhood and Microsoft ownership indicate legitimate cloud infrastructure operations.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionIA
CityDes Moines
TimezoneAmerica/Chicago
Latitude41.88
Longitude-93.10

🏒 Ownership & Registration

OrganizationMicrosoft Corporation
ASNAS8075
Network NameMSFT
CIDR Block52.145.0.0/16
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
17%
12
geolocation
35%
23
Overall24%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-22 19:33:20 UTC
Last Seen2026-08-12 17:17:08 UTC
Profile Built2026-08-12 17:31:45 UTC
Data FreshnessLive
Signal Types20
Total Observations22
πŸ” 20 signal types Β· 22 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.