IP Profile

🖥 52.101.170.2 — Microsoft Corporation

Microsoft Corporation · AS8075 · DE · 52.101.170.0/24 · Enriched · threat 0.50 · 1x · 0 sources · PTR mail-fr6p281cu00202.inbound.protection.outlook.com

reputation 36.1 (GUARDED) · first seen 3d ago · last seen 3d ago
No special flags ip medium-severity auto-tagged

Reputation

36.1
GUARDED

Threat Score

0.50
1 sightings

ASN

AS8075
from indicator

Peers on ASN

12
malicious co-tenants

Bad neighborhood

2
52.101.170.0/24

Country

DE
from indicator

🕵 Team Cymru Scout

Team Cymru Scout not configured — add config.scout.php or set cymruscout in API Config.

🌐 Network & Geo (local-first)

IP52.101.170.2
OrganizationMicrosoft Corporation
ASNAS8075
Netname
Netblock
Reverse DNS (PTR)mail-fr6p281cu00202.inbound.protection.outlook.com
CountryDE country intel

Identity resolves from the indicator's own columns first, then on demand from the local ip_ranges dataset by integer range — complete even before the bulk resolver runs.

🔥 Threat severity (AS8075 neighborhood)

High (.5-.75)
13
Avg threat 0.5 · peak 0.5 across 13 local IPs on AS8075

📁 Categories (ASN neighborhood)

🦠 Malware families (ASN neighborhood)

No local data.

🏷 Tags (ASN neighborhood)

medium-severity
13
ip
13
auto-tagged
13

🔌 Sources (ASN neighborhood)

IPsum level 1 (all)
5
stamparm ipsum
5
FireHOL: firehol_level4.netset
5
FireHOL: blocklist_net_ua.ipset
5
IPsum Level 1
5
IPsum Level 2
5
IPsum Level 3
5
Blocklist.de All
3
FireHOL level2
3
FireHOL level3
3
FireHOL: firehol_level2.netset
3
FireHOL: firehol_level3.netset
3
Blocklist.de: all
3
FireHOL: ciarmy.ipset
2

🌎 Geographic spread

📅 First-seen timeline

2026-08
13

Reporting Sources for this IP (0)

Not in local database, or no sources linked.

Passive DNS — domains resolving here (2)

52.101.170.2 2026-08-19 05:07:36

🏠 Same /24 — 52.101.170.0/24 (2 other malicious IPs)

Other flagged IPs in the same /24 — a concentration here suggests a compromised or abused block.

IPCategoryFamilyThreat
52.101.170.0 Enriched- dossier
52.101.170.1 Enriched- dossier
All in this subnet Bulk takedown

Case & Takedown Links

Cases

CASE-20260821-6BAD — DE — Country OPEN
CASE-20260821-3F31 — DE — Country OPEN
+ Case Takedown

Enrichments

ipinfo

Stored Enrichment Data Enrich Now

1 enrichment records on file (history preserved).

📁 Case Management

+ New case from this
Identity resolves local-first: the indicator's own asn/country columns, else on-demand integer-range lookup against the local ip_ranges dataset — so ASN, org and country populate even before the bulk resolver finishes and even for IPs not yet ingested. Analytics, neighborhood and graph render entirely from the local database; live reputation providers augment only when keys and outbound access are available.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php