## IP Intelligence Briefing: 52.180.137.70/32
Classification: Low Risk / Legitimate Infrastructure
Date of Analysis: 2026-07-30
---
**Executive Summary**
IP address 52.180.137.70 is a Microsoft Azure cloud infrastructure endpoint with a risk score of 25 (Low Risk). The IP belongs to Microsoft Corporation (ASN 8075) in the 52.145.0.0/16 CIDR block, geolocated to Boston, MA. No malicious indicators, threat campaigns, or abuse activity detected. The subnet shows clean classification with zero abuse density.
---
**Ownership & Infrastructure**
- Organization: Microsoft Corporation
- ASN: 8075 (MSFT)
- Network Block: 52.145.0.0/16
- Infrastructure Type: CloudCompute (Microsoft Azure)
- Country/Region: United States / US-MA
- City: Boston
- Registration: ARIN
---
**Threat Assessment**
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: 0 listings
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
**DNS & Resolution**
- PTR Hostname: azpdcgfwt7xy.stretchoid.com
- Reverse DNS: Forward confirmed
- DNS Classification: Microsoft Azure DNS pattern
---
**Network Neighborhood (52.180.137.0/24)**
- Abuse Density: 0 (Clean)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Neighbor Risk Distribution: 1 low-risk IP (52.180.137.14, risk score 25)
---
**Observation History**
- Total Observations: 17 signals
- Ownership Stability: 0 changes
- Threat Persistence: 0 days
- Threat Observation Count: 0
- Recent Signals (2026-07-30):
- Geolocation confirmed: Boston, US-MA (confidence 0.70)
- Organization confirmed: Microsoft Corporation (confidence 0.90)
- Subnet classification: Clean (confidence 0.40)
- Ownership changes: None recorded
---
**Services & Ports**
- Open Ports: None detected
- HTTP Services: None
- TLS Certificates: None
- Classification: Firewalled / No Services
---
**Recommended Actions**
No firewall rules or blocking actions recommended. The IP represents legitimate Microsoft Azure infrastructure with no observable malicious behavior. Standard cloud provider traffic should be allowed.
---
**SOC Analyst Notes**
This IP is part of Microsoft's Azure cloud infrastructure. The hostname pattern (azpdcgfwt7xy.stretchoid.com) is consistent with Microsoft Azure's DNS naming conventions. The subnet shows no abuse indicators, and the single active sibling IP shares the same low-risk profile. No threat intelligence or abuse signals detected. Traffic to/from this IP should be treated as benign cloud provider traffic.
Recommendation: No action required. Continue monitoring standard cloud provider traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.145.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | azpdcgfwt7xy.stretchoid.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | azpdcgfwt7xy.stretchoid.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 20% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 02:42:14 UTC |
| Last Seen | 2026-08-12 19:19:50 UTC |
| Profile Built | 2026-08-12 19:32:14 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.