IP Intelligence Briefing: 98.70.2.166
Date: 2026-06-10
---
**1. Core Profile**
- Reputation: Moderate Risk (Risk Score: 50)
- Ownership: Microsoft Corporation (ASN: AS8075)
- Geolocation:
- Country: US (geoPlausible: True)
- Region: Maharashtra, City: Pune (conflicting with Microsoft's global infrastructure; potential data error)
- Network Role: Microsoft Azure CloudCompute (firewalled, no services exposed)
- Threat Indicators:
- No direct malicious activity detected.
- Listed in 8 DNSBLs (high severity) but no active campaigns or known attacker associations.
---
**2. Observation History**
- Recent Activity (2026-06-10):
- DNSSEC Valid: True
- DNSBL Listings: 2 out of 8 lists (high severity)
- Threat Signals: 6 pulse detections (e.g., [nested data omitted])
- Geolocation Validation: ICMP blocked; unable to confirm physical location.
- Temporal Trends:
- No persistent malicious behavior detected.
- Threat observation count: 0.
---
**3. Relationships**
- Network Affiliations:
- Linked to MSFT (Microsoft Azure) via same subnet (98.70.0.0/15).
- No other subnets or organizations identified.
- DNS/Email:
- No SPF/DMArC records detected.
- No email authentication configurations.
---
**4. Neighborhood Analysis**
- Subnet: 98.70.2.166/24
- Abuse Density: 0% (clean subnet)
- Neighbors: No active or malicious sibling IPs identified.
---
**5. Recommendations**
- Verify Geolocation Discrepancy: Investigate conflicting location data (US vs. India) for potential misclassification.
- Monitor DNSBL Listings: Confirm if DNSBL entries are false positives or indicative of misconfigured Microsoft infrastructure.
- Network Segmentation: Ensure strict segmentation for Azure resources to mitigate lateral movement risks.
- Threat Intelligence Feeds: Cross-check with additional sources to validate DNSBL and pulse detections.
Conclusion: This IP is part of Microsoft's Azure infrastructure and shows no active malicious behavior. However, the DNSBL listings and geolocation anomalies warrant further investigation to rule out misconfigurations or false positives.
Source: IPDebrief Threat Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | auravex.aiwww.auravex.ai |
| Valid From | 2026-06-01T13:12:49+00:00 |
| Valid Until | 2026-08-30T13:12:48+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 06F115CF45A5AE2074B42FEA9A08394000CF |
| Thumbprint | 789B69B417D06154B05363A3C3BAFD58000E15EE |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 18% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-24 12:36:09 UTC |
| Last Seen | 2026-06-29 00:17:40 UTC |
| Profile Built | 2026-06-29 06:19:19 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.