IP Intelligence Briefing: 52.167.144.156
Date: June 12, 2026
---
**1. Core Profile**
- Ownership: Microsoft Corporation (ASN 8075, MSFT)
- Geolocation: Madison, WI, US (inferred via DNS and network signals)
- Network Role: Cloud compute resource (Bingbot), no open ports, no services detected.
- Threat Indicators: No malicious activity detected; moderate risk score (40/100).
- Subnet: 52.167.144.156/24, classified as "high_abuse" with 50.6% abuse density.
---
**2. Observation History**
- Recent Activity:
- Scanned for TLS/HTTP services (no active ports found).
- Classified as part of Microsoft's infrastructure (Bingbot).
- Geolocation validated via DNS and network signals, though ICMP probing failed (ICMP blocked).
- Trend: No persistent threats or campaign correlations detected.
---
**3. Relationships**
- Network: Linked to Microsoft's MSFT ASN (8075).
- DNS: Associated with `msnbot-52-167-144-156.search.msn.com` (Microsoft domain).
- Subnet: Part of a /24 subnet with 83 IPs, 38 active, 42 flagged as threats.
---
**4. Neighborhood Analysis**
- Subnet Risk: 50.6% abuse density (medium risk).
- Neighbor IPs:
- 72 IPs rated medium risk (40β50 score), 11 low risk.
- Notable neighbors include IPs with risk scores of 40β50 (e.g., 52.167.144.16, 52.167.144.18).
- Context: Subnet shows mixed usage, with potential for both legitimate and malicious activity.
---
**5. Recommendations**
- Monitoring: Track anomalies in the 52.167.144.156/24 subnet, especially given the high abuse density.
- Traffic Filtering: Consider allowing traffic to this IP for Microsoft services but monitor for unexpected behavior.
- Geolocation Verification: Validate location via alternative methods due to ICMP blocking.
Conclusion: This IP is part of Microsoft's infrastructure and appears benign, but its subnetβs abuse density suggests heightened scrutiny for potential lateral movement or compromised hosts.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.145.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | msnbot-52-167-144-156.search.msn.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | msnbot-52-167-144-156.search.msn.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 11 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 17:04:03 UTC |
| Last Seen | 2026-06-21 05:47:40 UTC |
| Profile Built | 2026-06-21 05:51:50 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 27 |
Full dossier details are available via our API.