Ask about Validation IP 40.127.240.158

Anonymous
2024-12-06T04:15:29+00:00

Hello Microsoft,

I am receiving traffic from internal to external IP (40.127.240.158) on my endpoint. Can you help me validate the IP 40.127.240.158? Based on my search, that IP is used by Microsoft.

However, upon further investigation, the IP is also listed as an IOC for the BianLian Ransomware, https://socradar.io/threat-actor-profile-bianlian-the-shape-shifting-ransomware-group/ Is that IP still being used by Microsoft?

Windows Server Networking

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes
Accepted answer
  1. Anonymous
    2024-12-10T09:45:15+00:00

    Hello,

    Yes, the IP address 40.127.240.158 is a valid Microsoft IP address. It is part of the Microsoft Azure cloud platform and is used for various services such as Azure Active Directory, Azure Virtual Machines, and Azure Storage.

    Best Regards

    Zunhui

    0 comments No comments

0 additional answers

Sort by: Most helpful