Intelligence Briefing: 52.98.149.130/32
The IP address 52.98.149.130/32 was identified as infrastructure owned by Microsoft Corporation (ASN 8075), geolocated to Redmond, Washington. Technical observation confirmed the address functions as a Web Server supporting HTTP (80) and HTTPS (443) services, utilizing a TLS certificate associated with outlook.com and Microsoft Corporation.
Threat assessment indicated a low-risk classification with a risk score of 0. No malicious indicators were present; the address carried zero blacklist entries, zero known campaigns, and zero observed incidents. The surrounding subnet (52.98.149.0/24) was classified as clean with no active threat siblings. Network behavior analysis showed no honeypot strikes or enumeration activity. Based on the absence of significant risk indicators, the operational recommendation was to allow traffic.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 52.96.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 5/7 domains |
| DMARC | 6/7 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 7 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Microsoft-HTTPAPI/2.0 |
| HTTP Title | β |
π TLS Certificate
| SANs | outlook.com*.hotmail.com*.internal.outlook.com*.live.com*.office.com*.office365.com*.outlook.com*.outlook.office365.comattachment.outlook.live.netattachment.outlook.office.net |
| Valid From | 2026-06-26T00:00:00+00:00 |
| Valid Until | 2027-01-10T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 198 days |
| Serial Number | 0E371D2766FD365DADDCF4004297839E |
| Thumbprint | C7C19E04464D744D810EF31A24C54FC22A7909C5 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 6 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 4 |
| ownership | 27% | 2 | 4 |
| reputation | 27% | 1 | 5 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-08 08:18:00 UTC |
| Last Seen | 2026-09-26 15:04:55 UTC |
| Profile Built | 2026-09-26 15:16:27 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 48 |
Full dossier details are available via our API.