# IP Intelligence Briefing: 4.194.1.91/32
Classification: LOW RISK / Cloud Infrastructure
Date: Intelligence compiled from IPDebrief platform data
Analysis Status: Complete
---
## Executive Summary
IP 4.194.1.91 is a Microsoft Azure cloud infrastructure address with an overall low risk score of 25. The IP belongs to Microsoft Corporation (ASN 8075, MSFT) within the 4.192.0.0/12 block. Geolocation indicates Singapore (SG). No active threat indicators are present. Historical data shows a single threat observation with no persistent malicious activity.
---
## Ownership & Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | Microsoft Corporation |
| **ASN** | 8075 |
| **Netname** | MSFT |
| **CIDR Block** | 4.192.0.0/12 |
| **Provider** | Microsoft Azure |
| **Infrastructure Type** | CloudCompute |
| **Classification** | Cloud, Hosting |
Geolocation: Singapore (latitude: 1.35, longitude: 103.82), Asia/Singapore timezone, accuracy radius 150km.
---
## Risk Assessment
| Metric | Value |
|---|---|
| **Risk Score** | 25 (Low) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Stability Label** | Not Applicable |
| **Abuse Confidence** | Not Reported |
| **Operator Score** | 0.1304 (Minimal) |
| **DNSBL Listed** | 1 of 8 lists |
Threat Indicators:
- No known attacker status
- Not a spam source
- Not a Tor exit node
- No known campaign affiliations
- No blacklist hits reported
---
## Network Behavior & Services
| Metric | Status |
|---|---|
| **Open Ports** | None detected |
| **Services** | No active services |
| **HTTP Title** | Not available |
| **TLS Certificate** | Not available |
| **PTR Hostnames** | None |
| **Forward Resolution** | Not confirmed |
| **Hosted Domains** | 0 |
| **Email Auth (SPF/DMARC)** | Not configured |
Control Plane Status:
- Route stable: Yes
- DNSSEC Valid: Yes
- Route Changes (30d): 0
- BGP Prefix: 4.192.0.0/12
---
## Neighborhood Analysis (4.194.1.0/24)
| Metric | Value |
|---|---|
| **Subnet** | 4.194.1.91/24 |
| **Abuse Density** | 0 |
| **Classification** | Mostly Clean |
| **Total Siblings** | 1 |
| **Active Siblings** | 0 |
| **Threat Siblings** | 1 |
| **Risk Distribution** | 0 High / 0 Medium / 0 Low |
The subnet shows minimal activity with no high or medium-risk neighbors.
---
## Historical Observations
Total Observations: 16 signals recorded
Observation Period: Multiple events as of July 22, 2026
Key Historical Signals:
- Subnet abuse density classification: mostly_clean (inherited risk: 2)
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 1
- Is persistently malicious: False
No escalation in risk profile detected over observation period.
---
## Relationship Graph
Total Relationships: 7
Relationship Types: All "Same Network" pointing to MSFT (Microsoft)
No external relationships detected (no hostnames, organizations, or certificates outside the Microsoft ecosystem).
---
## Recommended Actions
Current Risk Score: 25
Action Status: No immediate actions recommended
Firewall/Block Recommendations: None generated
Note: Probabilistic recommendations should be combined with additional context before operational implementation.
---
## Threat Intelligence Narrative
IP 4.194.1.91 represents Microsoft Azure cloud infrastructure with low risk characteristics. The address shows no active threat indicators, no open services, and no evidence of malicious behavior. Historical analysis confirms a single threat observation without persistent malicious activity. The subnet environment (4.194.1.0/24) demonstrates minimal abuse density and a "mostly clean" classification.
Monitoring Recommendation: Standard monitoring appropriate. No immediate defensive action required. The IP should be evaluated in the context of broader Microsoft Azure infrastructure risk management.
IOC Status: No IOCs (Indicators of Compromise) to add to threat intelligence feeds.
---
Report Generated By: IPDebrief Intelligence Platform
Data Currency: Real-time analysis based on available intelligence sources
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 4.192.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting — Infrastructure provider without advanced routing |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS8075 |
| Network Prefix | 4.192.0.0/12 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:21:52 UTC |
| Last Seen | 2026-08-22 17:37:02 UTC |
| Profile Built | 2026-08-29 10:18:34 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 4.194.1.91
Who owns the IP address 4.194.1.91?
4.194.1.91 is registered to Microsoft Corporation. The address falls within the 4.192.0.0/12 network block. Registration is held at ARIN.
Where is 4.194.1.91 located?
Geolocation data places 4.194.1.91 in Singapore, SG, Singapore. The local time zone is Asia/Singapore. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 4.194.1.91 malicious or safe?
4.194.1.91 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
Is 4.194.1.91 a VPN, proxy, or data center address?
4.194.1.91 is classified as cloud infrastructure and hosting infrastructure based on network ownership and behavioural analysis.