IP INTELLIGENCE BRIEFING: 52.225.35.113/32
ASSIGNED RISK RATING: LOW (25/100)
SUMMARY
IP 52.225.35.113 is a Microsoft Azure cloud infrastructure address classified as low risk with no active threat indicators. The address belongs to Microsoft Corporation (ASN 8075) within the 52.224.0.0/11 CIDR block, with geolocation anchored in San Francisco, CA.
OWNERSHIP & INFRASTRUCTURE
- Organization: Microsoft Corporation
- ASN: 8075 (MSFT)
- CIDR Block: 52.224.0.0/11
- Infrastructure Type: CloudCompute (Microsoft Azure)
- Network Role: Cloud hosting with firewalled/no services exposed
- Registration: ARIN
THREAT INDICATORS
- Abuse Confidence Score: Not applicable
- Blacklist Status: Listed on 1 of 8 DNSBL lists
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Active Threat Indicators: None
- Known Campaigns: None detected
NETWORK BEHAVIOR
- Open Ports: None detected
- DNS PTR Hostnames: None
- Forward Resolution: Not confirmed
- Service Banners: None observed
- Control Plane Status: Route stability flagged as unstable; minimal operator score (0.1304)
- Traceroute: 24 hops via Comcast transit networks
TEMPORAL ANALYSIS
- 17 historical observations recorded
- Recent operator assessment (2026-08-05): Minimal risk (0.15)
- Threat persistence: None
- Persistent malicious behavior: False
- Ownership changes: None observed
SUBNET ANALYSIS (52.225.35.0/24)
- Abuse Density: 0%
- Subnet Classification: Clean
- Threat Siblings: 0
- Active Siblings: 0
- High/Medium Risk Neighbors: 0
RELATIONSHIPS
- 5 relationships identified, all indicating same network affiliation with MSFT
- No external entity relationships detected
RECOMMENDATIONS
No specific firewall rules or blocking actions recommended. The IP demonstrates standard Microsoft Azure cloud behavior with no malicious activity patterns. Continue standard monitoring; no immediate action required.
INTEL CONCLUSION
This IP represents legitimate Microsoft Azure cloud infrastructure with clean threat posture. The single DNSBL listing warrants awareness but does not indicate active compromise. SOC teams should maintain standard monitoring protocols without special handling.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.224.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 50% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 21:01:09 UTC |
| Last Seen | 2026-08-12 20:00:46 UTC |
| Profile Built | 2026-08-12 20:13:17 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.