# IP Intelligence Briefing: 74.248.24.145/32
## Executive Summary
IP address 74.248.24.145 is a Microsoft Azure cloud compute infrastructure endpoint with moderate risk scoring (65). The IP is associated with Microsoft Corporation (ASN 8075) and operates within the 74.248.0.0/15 CIDR block registered with ARIN. Current geolocation consensus places the infrastructure in Warsaw, Poland, with geographic validation inconsistencies across sources.
## Technical Profile
- Risk Score: 65 (Moderate Risk)
- Provider: Microsoft Azure (CloudCompute infrastructure)
- Organization: Microsoft Corporation
- ASN: 8075
- Geolocation: Warsaw, Mazovia region, Poland (PL)
- Infrastructure Type: CloudCompute / Hosting
- Connection Type: Firewalled / No Services Detected
## Threat Assessment
- Abuse Confidence: Low (No active threat indicators)
- Blacklist Status: Listed on 3 of 8 DNSBLs (DNSBL Listed Count: 3)
- Known Threats: None detected
- Campaign Associations: No known campaign matches
- Tor Exit/VPN/Proxy: Not identified
- Active Ports: None observed
## Infrastructure Context
- Network Classification: Microsoft Azure cloud infrastructure
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC: Valid
- Geographic Validation: Inconsistent signals between Polish and US geolocation sources
- Service Presence: No open ports, no active TLS certificates, no HTTP services
## Historical Observation
12 signal observations tracked. Recent data confirms:
- Persistent Microsoft Corporation ownership
- Consistent cloud infrastructure classification (Microsoft Azure)
- Geographic signals show mixed data sources (Poland and United States)
- No evidence of ownership changes or persistent malicious activity
## Neighborhood Analysis
Subnet: 74.248.24.0/24
- Abuse Density: 0 (Low neighborhood risk)
- Total Neighbors: 1
- Neighbor Risk: 74.248.24.188 (Risk Score: 25)
- Risk Distribution: 1 Low Risk, 0 Medium, 0 High
## Relationship Graph
- Associated Entity: MSFT (Same Network)
- No additional relationships to organizations, certificates, or hostnames detected
## Recommended Actions
The IP exhibits characteristics of legitimate cloud infrastructure. While the moderate risk score (65) and DNSBL listings warrant monitoring, no immediate blocking is recommended. The IP is:
1. Part of Microsoft's Azure cloud infrastructure
2. Operating in Warsaw data center region
3. Not associated with active threat campaigns
4. Located in a low-abuse-density subnet
## Intelligence Narrative
IP 74.248.24.145 represents Microsoft Azure cloud compute infrastructure deployed in the Warsaw region. The moderate risk scoring stems primarily from DNSBL listings rather than active malicious behavior. No threat indicators, known attacker signatures, or campaign associations were identified. The IP operates within a clean neighborhood (74.248.24.0/24) with minimal abuse density. Operational characteristics align with legitimate cloud hosting infrastructureβfirewalled with no exposed services. While geographic data sources show some inconsistency between Polish and US origins, this is consistent with Microsoft's multi-region cloud deployment architecture. Monitoring recommended for the DNSBL listings, but no immediate defensive action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 74.248.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 10:34:37 UTC |
| Last Seen | 2026-08-12 23:36:28 UTC |
| Profile Built | 2026-08-12 23:50:28 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.