IP INTELLIGENCE BRIEFING: 52.238.198.168/32
Classification: Cloud Infrastructure β Microsoft Azure
Risk Level: Moderate (Score: 40/100)
Date of Analysis: 2026-07-30
---
**OWNERSHIP & NETWORK CLASSIFICATION**
The target IP 52.238.198.168 belongs to Microsoft Corporation (ASN 8075, MSFT) within the 52.224.0.0/11 CIDR block. The address is classified as Microsoft Azure cloud compute infrastructure, functioning as a web server. Geolocation data places the IP in Des Moines, Iowa (41.88°N, -93.1°W) with 80% confidence. The IP is not bogon, residential, or mobile traffic.
**THREAT ASSESSMENT**
Current Risk Indicators:
- No active threat indicators detected
- No known attacker reputation
- No Tor exit node association
- Not identified as a spam source
- Zero blacklist entries in active threat feeds (Pulsedive, abuse.ch, etc.)
- No known campaign affiliations
DNSBL Status: Listed on 2 out of 8 total DNSBL lists (control plane data). This may indicate historical reputation issues or specific service misconfigurations.
Abuse Density: Neighborhood abuse density scored at 0.5 (medium) in profile data; however, subnet-level analysis shows abuse density of 0 with 1 low-risk sibling IP (52.238.198.211).
**NETWORK SERVICES & FINGERPRINTING**
Open Ports: TCP/443 (HTTPS)
Server Fingerprint: Kestrel (ASP.NET Core web server)
TLS Certificate: Self-signed certificate issued for "e2etestsworker.localhost" (CN=e2etestsworker.localhost)
DNS Records: No PTR hostnames; forward resolution not confirmed
The Kestrel server banner indicates Microsoft Azure-hosted web application infrastructure.
**OBSERVATION HISTORY**
Fifteen signal observations recorded over the monitoring period. Ownership remains consistently attributed to Microsoft Corporation across all observations. Geographic inference shows consistent placement in Iowa with RTT validation confirming plausible distance from probe location (7,066.3 km). No ownership changes observed; threat observation count remains at zero.
**RELATIONSHIPS & NEIGHBORHOOD**
Relationship Graph: Single relationship identifiedβSame Network with MSFT (Microsoft).
/24 Neighborhood (52.238.198.0/24):
- Total siblings: 2
- Active siblings: 2
- Threat siblings: 1 (neighbor IP: 52.238.198.211, risk score: 25)
- Classification: mostly_clean
**SECURITY ACTIONS & RECOMMENDATIONS**
For SOC Analysts:
- Treat as legitimate cloud infrastructure; no immediate blocking recommended
- Monitor for abuse patterns if associated with 52.238.198.211 (neighbor with elevated risk)
- Review DNSBL listings to determine specific reasons for blacklisting
- Verify HTTPS service functionality if traffic analysis indicates anomalies
Recommended Actions:
- No immediate firewall rules recommended (actions endpoint returned empty recommendations)
- Standard Azure cloud traffic monitoring procedures apply
- If inbound traffic to port 443 from this IP is unexpected, verify with Microsoft Azure support via abuse@microsoft.com
**CONTROL PLANE DATA**
- RPKI State: Not reported
- IRR Consistency: Not reported
- Route Stability: False (route changes in last 30 days)
- Operator Score: 0.1304 (Minimal)
- DNSSEC Valid: True
- Delegation Age: Not reported
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.224.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 27% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 16:14:37 UTC |
| Last Seen | 2026-08-12 22:46:00 UTC |
| Profile Built | 2026-08-12 23:03:41 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.