# IP Intelligence Briefing: 52.176.138.183
## Executive Summary
IP address 52.176.138.183 is identified as a Microsoft Azure cloud infrastructure endpoint with a low risk profile (Risk Score: 25). The IP shows no malicious indicators and belongs to a clean subnet with minimal abuse density.
## Ownership and Classification
- Organization: Microsoft Corporation (ASN 8075, MSFT)
- Network Block: 52.145.0.0/16
- Classification: Microsoft Azure CloudCompute infrastructure
- Geolocation: Des Moines, IA, US (geolocation consensus confirmed)
- Network Role: Provider/Hosting with no open services detected
## Threat Assessment
- Overall Risk Score: 25 (Low Risk)
- Blacklist Status: Not listed on any threat feeds
- Threat Indicators: None detected (not a known attacker, spam source, or Tor exit node)
- Abuse Confidence Score: Not applicable
- Known Campaigns: None correlated
## Network Behavior
- Services: No open ports detected; classified as "Firewalled / No Services"
- DNS: No PTR hostnames or forward resolution detected
- Control Plane: DNSSEC valid; minimal operator score (0.1304)
- Route Stability: Not stable; no recent route changes (0 changes in 30 days)
- Traceroute: 22 hops with 6 timed-out; transit through Comcast
## Subnet Context
- Subnet: 52.176.138.0/24
- Abuse Density: 0.0 (clean classification)
- Active Siblings: 2 IPs in subnet
- Threat Siblings: 0
- Neighbor IP: 52.176.138.197 (Risk Score: 25, Authority Score: 50)
## Observation History
- Total Observations: 19 signals over time
- Most Recent Activity: 2026-08-13
- Signal Types: Geolocation, routing, DNS, reputation, and network service signals
- Threat Persistence: 0 days (not persistently malicious)
- Campaign Likelihood: None
## Recommended Actions
- Allow Traffic: Permitted by default given low risk profile
- Monitoring: Standard observation recommended; no blocking required
- Firewall Rules: No restrictive rules needed based on current risk profile
## Conclusion
IP 52.176.138.183 represents legitimate Microsoft Azure cloud infrastructure with no observed malicious activity. The IP belongs to a clean subnet with no threat siblings and demonstrates normal cloud provider behavior. No defensive actions required beyond standard network monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.145.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-01 04:26:00 UTC |
| Last Seen | 2026-08-13 02:27:41 UTC |
| Profile Built | 2026-08-13 02:50:11 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.