A tool that provides visibility, control, and threat protection for cloud-based applications and services
Nope, these IP addresses are not part of Microsoft services. Public WHOIS data and network routing information show that all five IP addresses belong to Ethio Telecom (the national telecommunications provider in Ethiopia). They are hosted under Autonomous System Number AS24757.
A breakdown of the network ownership for each IP address indicates:
- 196.189.145.143 – Assigned to Ethio Telecom (Network Range:
196.189.0.0/18) - 196.188.255.172 – Assigned to Ethio Telecom (Network Range:
196.188.0.0/14) - 196.190.154.244 – Assigned to Ethio Telecom (Network Range:
196.190.0.0/17) - 196.188.252.163 – Assigned to Ethio Telecom (Network Range:
196.188.0.0/14) - 196.190.62.87 – Assigned to Ethio Telecom (Network Range:
196.190.62.0/24)
Because these are consumer/enterprise ISP addresses rather than cloud infrastructure IPs, the security alerts likely stem from individual compromised devices, local web servers, or end-users on that provider's network.
If you are experiencing malicious activity (such as scanning, brute-force attacks, or spam), you can forward your logs directly to Ethio Telecom's abuse contacts, which can be found via the regional internet registry AFRINIC
For future investigations, you can cross-reference suspicious IPs with official, dynamically updated Microsoft Azure IP ranges by checking the Microsoft Azure IP Ranges and Service Tags JSON file.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin