# IP Intelligence Briefing: 4.194.22.129
Classification: Cloud Infrastructure Endpoint | Risk Assessment: Moderate Risk (Score: 40) | Last Updated: Current
---
## Executive Summary
IP address 4.194.22.129 is a Microsoft Azure cloud compute endpoint located in Singapore (ASN 8075/MSFT). While the IP is part of Microsoft's trusted infrastructure, it registers DNSBL listings on 2 of 8 threat intelligence feeds. The asset shows minimal threat characteristics with no open services or active ports. No evidence of persistent malicious behavior or campaign correlation detected.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | Microsoft Corporation (MSFT) |
| **ASN** | 8075 |
| **CIDR Block** | 4.192.0.0/12 |
| **Geolocation** | Singapore, SG |
| **Network Role** | Microsoft Azure / CloudCompute |
| **Infrastructure Type** | Cloud Infrastructure |
| **DNSSEC Valid** | Yes |
| **Risk Score** | 40 (Moderate) |
---
## Threat Indicators
- DNSBL Listings: 2 of 8 total lists flagged
- Threat Feed Indicators: None
- Known Campaigns: None
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Abuse Confidence Score: Not applicable (cloud endpoint)
---
## Network Neighborhood Analysis
The /24 subnet (4.194.22.0/24) shows:
- Abuse Density: 0
- Subnet Classification: Clean
- Risk Distribution: No high/medium/low risk siblings detected
- Active Siblings: 0
- Threat Siblings: 0
No adjacent IPs show correlated threat activity, indicating isolated endpoint behavior.
---
## Observation History (17 Total Signals)
Recent Activity:
- 2026-08-04: Minimal threat operator score (0.1304), low confidence (0.30)
- 2026-07-23: Minimal threat profile with DNSSEC validation present
- DNSBL Signal: High-severity listing detected on 2026-08-04 across 8 total lists
Temporal Trends:
- No persistent malicious behavior observed
- Ownership changes: 0
- Threat observation count: 0
- Threat persistence days: 0
---
## Relationship Graph
Three relationships identified, all mapping to the same Microsoft network infrastructure (MSFT). No additional entity relationships detected (no hostnames, certificates, or organizational links beyond the network association).
---
## Recommended Actions
1. Monitor DNSBL Variations: Track changes in blacklist status across the 8 registered lists
2. Allow Traffic (Standard): Azure endpoints are generally trusted; permit standard cloud traffic patterns
3. No Blocking Required: Risk score of 40 is within acceptable thresholds for Microsoft Azure infrastructure
4. Baseline Services: Confirm no unexpected service discovery or port exposure on this endpoint
---
## SOC Analyst Notes
This IP represents legitimate Microsoft Azure cloud infrastructure. The moderate risk rating (40) is primarily driven by DNSBL listings that may reflect legitimate cloud traffic patterns rather than malicious activity. No firewall blocking recommended. Continue standard monitoring for Azure endpoints within the 4.192.0.0/12 block.
Confidence Level: High (Cloud infrastructure with established reputation)
Recommended Priority: Low (Standard monitoring)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 4.192.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting — Infrastructure provider without advanced routing |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS8075 |
| Network Prefix | 4.192.0.0/12 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 25% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-03 04:41:22 UTC |
| Last Seen | 2026-08-25 00:38:29 UTC |
| Profile Built | 2026-08-29 09:19:09 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 4.194.22.129
Who owns the IP address 4.194.22.129?
4.194.22.129 is registered to Microsoft Corporation. The address falls within the 4.192.0.0/12 network block. Registration is held at ARIN.
Where is 4.194.22.129 located?
Geolocation data places 4.194.22.129 in Singapore, SG, Singapore. The local time zone is Asia/Singapore. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 4.194.22.129 malicious or safe?
4.194.22.129 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
Is 4.194.22.129 a VPN, proxy, or data center address?
4.194.22.129 is classified as cloud infrastructure based on network ownership and behavioural analysis.