# IP INTELLIGENCE BRIEFING
Target IP: 52.165.63.205/32
Classification: Microsoft Azure Cloud Infrastructure
Risk Level: Moderate Risk (Score: 40)
Date Generated: 2026-08-05
---
## EXECUTIVE SUMMARY
IP 52.165.63.205 is a Microsoft Azure cloud compute resource located in Des Moines, Iowa. The IP demonstrates moderate risk primarily driven by DNSBL listings (2 of 8 lists), though no active threat indicators or malicious behavior observed. The /24 neighborhood is classified as clean with zero abuse density, suggesting legitimate enterprise cloud operations.
---
## OWNERSHIP & INFRASTRUCTURE
Organization: Microsoft Corporation
ASN: 8075 (MSFT)
Network Block: 52.145.0.0/16
Infrastructure Type: Cloud Compute (Microsoft Azure)
Geolocation: United States, Iowa, Des Moines (41.88°N, 93.1°W)
Timezone: America/Chicago
---
## THREAT INDICATORS
Current Risk Score: 40/100 (Moderate)
Abuse Confidence: Not reported
Blacklist Status: Listed on 2 of 8 DNSBL feeds (max severity: high)
Known Attacker: No
Spam Source: No
Tor Exit Node: No
Campaign Association: None detected
Threat Feeds: Empty
Known Campaigns: None
---
## NETWORK SERVICES & DNS
Open Ports: None detected
TLS Certificate: None
HTTP Title: None
PTR Resolution: None
Forward DNS: Not confirmed
Email Authentication: SPF/DMARC not configured
Hosted Domains: 0
---
## CONTROL PLANE DATA
BGP Prefix: 52.160.0.0/11
Route Stability: False
RPKI State: Not reported
IRR Consistency: Not reported
Route Changes (30d): 0
DNSSEC Valid: Yes
Operator Score: 0.1304 (Minimal)
DNSBL Listed: Yes (2/8 lists)
---
## HISTORICAL OBSERVATIONS
Total Signals Observed: 17
Observation Period: Recent activity from JulyβAugust 2026
Key Historical Signals:
- Geolocation consistently reported as Des Moines, IA
- Operator scores showing minimal threat level (0.1304)
- Multiple DNSBL listing signals detected
- Service scanning events with no open ports
- No persistent malicious behavior observed
Threat Persistence: None
Ownership Changes: 0
---
## RELATIONSHIP GRAPH
Connected Entities: 5
Relationship Type: Same Network (MSFT)
Network Affiliation: All relationships map to Microsoft (MSFT) infrastructure
---
## NEIGHBORHOOD ANALYSIS
Subnet: 52.165.63.0/24
Abuse Density: 0 (Clean)
Risk Distribution: High: 0, Medium: 0, Low: 0
Active Siblings: 0
Threat Siblings: 0
Total Siblings: 1
---
## SECURITY RECOMMENDATIONS
Action: Monitor but do not block. This is legitimate Microsoft Azure infrastructure.
Recommended Actions:
1. Allow traffic from this IP β Microsoft Azure cloud resource
2. Monitor DNSBL listing sources for context on reputation concerns
3. No firewall rules required for this IP
4. Consider whitelisting for Microsoft cloud traffic if applicable
Risk Context: The moderate risk score (40) is primarily driven by DNSBL listings rather than active malicious behavior. The clean /24 neighborhood and Microsoft ownership indicate legitimate cloud infrastructure operations.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.145.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-22 19:33:20 UTC |
| Last Seen | 2026-08-12 17:17:08 UTC |
| Profile Built | 2026-08-12 17:31:45 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.