IP Intelligence Briefing: 52.167.144.177
Date: 2026-06-13
---
**1. Core Profile**
- Risk Score: Moderate (40/100)
- Provider: Bingbot (Microsoft)
- Geolocation:
- Country: United States (US)
- Region: Massachusetts (Boston)
- City: Boydton, Virginia (conflicting data)
- Network Role:
- Botnet node (Bingbot)
- No open services or TLS certificates detected
- BGP prefix: `52.160.0.0/11` (Comcast transit)
---
**2. Threat Indicators**
- No direct malicious indicators (no malware, phishing, or spam associations).
- DNS Associations:
- Linked to `msnbot-52-167-144-177.search.msn.com` (Microsoft Search bot).
- Subnet Abuse:
- /24 subnet (`52.167.144.177/24`) has high abuse density (0.5181).
- 43/83 siblings flagged as threats (20% inherited risk).
- 49 active neighbors with mixed risk scores (31 medium, 51 low).
---
**3. Observation History**
- Recent Activity (2026-06-13):
- Geolocation resolved to Boydton, Virginia (possibly spoofed).
- BGP route stability: unstable (route changes detected).
- DNSSEC validation: valid;CAA records present.
- 1/8 DNSBL listings (low-severity).
---
**4. Relationships**
- DNS:
- PTR hostname: `msnbot-52-167-144-177.search.msn.com` (Microsoft).
- SPF/DMArc records detected; no email abuse.
- Network:
- BGP origin ASN: 8075 (Microsoft).
- Route stability: unstable (30-day analysis).
---
**5. Recommendations**
- Monitor Subnet: High abuse density in `52.167.144.177/24` warrants closer scrutiny.
- Block IP: Consider blocking if botnet activity escalates (e.g., DDoS, data exfiltration).
- Verify Geolocation: Discrepancy between Boston and Boydton may indicate spoofing.
- Check Neighbors: 43/83 siblings flagged as threats; investigate lateral connections.
---
Note: This IP appears to be a legitimate Bingbot node but resides in a subnet with elevated risk. SOC teams should prioritize monitoring and correlate with other indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.145.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | msnbot-52-167-144-177.search.msn.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | msnbot-52-167-144-177.search.msn.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 20% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-05 19:24:12 UTC |
| Last Seen | 2026-06-21 12:39:41 UTC |
| Profile Built | 2026-06-21 12:44:02 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.