IP INTELLIGENCE BRIEFING: 52.224.240.74/32
Classification: Microsoft Azure Cloud Infrastructure (Low Risk)
Report Date: Current Analysis Cycle
Analyst: Automated IPDebrief Intelligence System
---
EXECUTIVE SUMMARY
IP address 52.224.240.74 is a Microsoft Azure cloud compute resource (AS8075) located in Virginia, US. Current risk assessment indicates Low Risk (score: 25/100). The IP resides within the 52.224.0.0/11 CIDR block and operates as Microsoft infrastructure with no active threat indicators. Historical observations show transient threat signals and limited DNSBL listings, but the IP currently shows no active malicious behavior.
---
OWNERSHIP & GEOGRAPHY
- Organization: Microsoft Corporation (AS8075)
- Network Name: MSFT
- CIDR Block: 52.224.0.0/11
- Geolocation: Virginia, US (37.37°N, -79.46°W)
- Infrastructure Type: CloudCompute (Microsoft Azure)
- Service Purpose: Firewalled / No Services
---
THREAT ASSESSMENT
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable (cloud infrastructure)
- Blacklist Status: 1 out of 8 DNSBL lists (historical)
- Known Campaigns: None
- Threat Indicators: None detected
- Reputation Labels: Clean neighborhood classification
Current Status: No active threat indicators. IP is not flagged as Tor exit, known attacker, or spam source.
---
NETWORK CONTEXT
- Subnet: 52.224.240.74/24
- Abuse Density: 0.00 (Clean)
- Threat Siblings: 0
- Network Classification: Legitimate cloud infrastructure
- BGP Prefix: 52.224.0.0/11
- Route Stability: Unstable (route changes observed)
---
OBSERVATION HISTORY
Recent signal history reveals:
- Multiple threat-related signals observed between June 2026
- One DNSBL listing with high severity severity rating
- Operator score: 0.1304 (Minimal)
- Some signals indicate transient threat activity (has_threats: true in historical observations)
- Geo-validation: ICME blocked during probe attempts
---
RELATIONSHIPS
All relationship links point to Microsoft (MSFT) network entities. No external organizational relationships or certificate associations identified.
---
RECOMMENDED ACTIONS
Current Risk Profile: Low
- No specific firewall rules recommended
- Standard Microsoft Azure security posture applies
- Monitor for any change in risk score above threshold (50)
- No immediate blocking required
SOC Analyst Notes: This is legitimate Microsoft Azure infrastructure. The historical DNSBL listing and transient threat signals appear to be legacy artifacts rather than current threat indicators. Standard cloud security monitoring applies. No blocking recommended at this time.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.224.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 33% | 2 | 4 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-30 10:59:37 UTC |
| Last Seen | 2026-06-29 07:47:12 UTC |
| Profile Built | 2026-06-29 07:49:47 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.