IP INTELLIGENCE BRIEFING: 74.249.212.138
Classification: MODERATE RISK (Score: 40/100)
---
EXECUTIVE SUMMARY
Target IP 74.249.212.138 is an Azure-hosted infrastructure endpoint belonging to Microsoft Corporation (ASN 8075). Despite legitimate provider attribution, the IP exhibits concerning indicators including self-signed localhost certificates, 404 HTTP responses, and presence on 2 of 8 DNSBLs. Network neighborhood analysis indicates 2 threat siblings within the /24 subnet. Recommend defensive blocking pending further assessment.
---
OWNERSHIP & GEOLOCATION
- Organization: Microsoft Corporation (AS8075, MSFT)
- CIDR Block: 74.248.0.0/15
- Location: Des Moines, IA, US (RIR: ARIN)
- Registration: Available via RDAP
- Infrastructure Type: CloudCompute (Microsoft Azure)
---
NETWORK SERVICES & FINGERPRINT
- Active Service: TCP/443 (HTTPS)
- Server Stack: Kestrel (.NET framework)
- HTTP Version: 2.0
- Time-to-First-Byte: 740ms
- Response Status: 404 (Not Found)
- TLS Certificate: Self-signed for e2etestsworker.localhost
- Security Headers: No CSP, HSTS, or referrer policy implemented
---
THREAT INDICATORS
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not calculated
- Threat Observation Count: 1
- Threat Persistence Days: 0
---
NEIGHBORHOOD ANALYSIS (74.249.212.0/24)
- Subnet Classification: Mostly Clean
- Abuse Density: 0
- Total Siblings: 2 (both active)
- Threat Siblings: 2
- Inherited Risk: 5
- Neighbor Profile: 74.249.212.250 (Risk: 25, Authority: 50)
---
HISTORICAL OBSERVATIONS
Recent signal analysis (20 observations) shows consistent subnet classification as "mostly_clean" with abuse density of 1. HTTP fingerprinting indicates persistent Kestrel server presence with 404 responses and no security headers implemented.
---
RELATIONSHIP GRAPH
17 network-level relationships identified, all associating with Microsoft (MSFT) infrastructure. No direct hostname, organization, or certificate relationships beyond provider attribution.
---
RECOMMENDED DEFENSIVE ACTIONS
Firewall Blocking Rules:
- iptables: `iptables -A INPUT -s 74.249.212.138 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 74.249.212.138 drop`
- nginx: `deny 74.249.212.138;`
- pfSense: `74.249.212.138/32`
- Cloudflare WAF: Block IP (Risk Score 40)
- AWS WAF: Add to blocklist (CIDR: 74.249.212.138/32)
Analyst Notes:
While the IP is attributed to legitimate Microsoft Azure infrastructure, the combination of localhost certificate (e2etestsworker.localhost), 404 responses, DNSBL listings, and threat siblings warrants defensive blocking. Monitor for any legitimate Microsoft services that may legitimately route through this address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 74.248.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Kestrel |
| HTTP Title | β |
π TLS Certificate
| SANs | e2etestsworker.localhoste2etestsworker.localhost |
| Valid From | 2026-05-29T23:31:34+00:00 |
| Valid Until | 2027-05-29T23:51:34+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 1B8E0061A8F17DB445183746BE7925DC |
| Thumbprint | E56FAED07F47A64DB642978F818154691CA7BCBF |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-26 12:52:27 UTC |
| Last Seen | 2026-06-29 03:12:32 UTC |
| Profile Built | 2026-06-29 15:16:33 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.