# INTELLIGENCE BRIEFING: 4.193.187.18/32
## EXECUTIVE SUMMARY
IP address 4.193.187.18 is classified as Low Risk (risk score: 25) and represents Microsoft Azure cloud infrastructure. No malicious activity or threat indicators have been observed. The IP is part of Microsoft's legitimate address space (AS8075, 4.192.0.0/12) with geolocation in Singapore.
---
## OWNERSHIP & INFRASTRUCTURE
- Organization: Microsoft Corporation (MSFT)
- ASN: AS8075
- CIDR Block: 4.192.0.0/12
- Network Name: MSFT
- Infrastructure Type: CloudCompute (Microsoft Azure)
- Classification: Cloud hosting infrastructure
- Geolocation: Singapore (SG), Asia/Singapore timezone
- Provider Score: 0 / Authority Score: 0 / Stability Score: 0
---
## THREAT ASSESSMENT
Current Risk Profile:
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Known Campaigns: None detected
- Threat Feeds: Clean
Control Plane Indicators:
- Origin ASN: 8075
- BGP Prefix: 4.192.0.0/12
- Route Changes (30d): 0
- Route Stability: Unstable
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 total lists
- Operator Score: 0.1304 (Minimal)
---
## OBSERVATION HISTORY (16 Total Signals)
Recent signal observations indicate:
- Most Recent (2026-08-04): Minimal operator score (0), no active threat signals
- Geolocation Signals: Confirmed Singapore location (lat: 1.35, lon: 103.82)
- Network Classification: Microsoft Azure cloud infrastructure confirmed
- Historical Data: No persistent malicious activity detected
- Threat Persistence Days: 0
---
## NETWORK NEIGHBORHOOD
- Subnet: 4.193.187.18/24
- Abuse Density: 0% (Clean classification)
- Risk Distribution: 0 high, 0 medium, 0 low risk neighbors
- Active Siblings: 0
- Threat Siblings: 0
- Neighbor Count: 0
---
## RELATIONSHIP GRAPH
- Total Relationships: 6
- Relationship Types: All "Same Network" pointing to MSFT
- Associated Entities: Microsoft Corporation network infrastructure
---
## SERVICES & DNS
- Open Ports: None detected
- TLS Certificates: None
- HTTP Title/Server Banner: None (Firewalled / No Services)
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Auth (SPF/DMARC): Not configured
---
## SECURITY ACTIONS & RECOMMENDATIONS
Recommended Actions: None
Firewall Rules: Not required
Risk-Based Classification: Low Risk / Legitimate Cloud Infrastructure
---
## ANALYST NOTES
This IP address represents normal Microsoft Azure cloud infrastructure operating from Singapore. The low risk score (25) and absence of threat indicators, blacklist entries, or malicious activity patterns indicate benign cloud hosting. The IP shows no open services and is properly routed within Microsoft's BGP announcement space. No immediate security actions are required.
Classification: LOW RISK / LEGITIMATE INFRASTRUCTURE
Recommended Handling: Monitor as part of normal cloud traffic; no blocking or filtering required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 4.192.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting — Infrastructure provider without advanced routing |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| 8443 | https-alt | tcp | — |
| Closed Ports | 25, 3389, 8080 (4 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | www.test.com |
| Valid From | 2026-07-10T05:30:14+00:00 |
| Valid Until | 2036-07-07T05:30:14+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
🛡️ Public Network Snapshot
| Origin ASN | AS8075 |
| Network Prefix | 4.192.0.0/12 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 39% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 27% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-03 16:58:21 UTC |
| Last Seen | 2026-08-22 16:34:16 UTC |
| Profile Built | 2026-08-29 10:23:45 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 4.193.187.18
Who owns the IP address 4.193.187.18?
4.193.187.18 is registered to Microsoft Corporation. The address falls within the 4.192.0.0/12 network block. Registration is held at ARIN.
Where is 4.193.187.18 located?
Geolocation data places 4.193.187.18 in Singapore, SG, Singapore. The local time zone is Asia/Singapore. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 4.193.187.18 malicious or safe?
4.193.187.18 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 4.193.187.18?
Responsive ports observed on 4.193.187.18 include 80, 443, 22, 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 4.193.187.18 a VPN, proxy, or data center address?
4.193.187.18 is classified as cloud infrastructure and hosting infrastructure based on network ownership and behavioural analysis.