We have outgoing traffic from an IP address belonging to Microsoft with a bad reputation "13.107.4.50", is it malicious?

Misael Enriquez Viramontes 0 Reputation points
2024-01-30T00:42:23.0433333+00:00

Hello everyone, we regularly ingest indicators of compromise into our threat protection systems from different intelligence sources. We noticed that there is an IP address belonging to Microsoft/Azure "13.107.4.50", which according to these sources belongs to the "BlackByte" threat. We have been investigating on some sites where they describe that this address belongs to Microsoft update services, however in other cases they mention that it is known as a malware spreader. Has anyone dealt with this case? Could you help us with the verdict to know if we have to block or allow this IP? Thanks and regards!

Windows for business | Windows Server | Devices and deployment | Configure application groups
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.