# IP Intelligence Briefing: 4.194.24.143/32
Classification: Moderate Risk Cloud Infrastructure IP
Report Date: 2026-08-12
Analyst: SOC Intelligence Division
---
## EXECUTIVE SUMMARY
IP 4.194.24.143 is a Microsoft Azure cloud infrastructure endpoint registered to Microsoft Corporation (ASN 8075). The IP presents moderate risk (score: 60) primarily due to its classification as cloud hosting infrastructure with a single DNSBL listing. No active threat indicators or malicious campaigns were detected. The IP is part of the 4.192.0.0/12 CIDR block and is located in Singapore.
---
## PROFILE ANALYSIS
Ownership & Network:
- Organization: Microsoft Corporation
- ASN: 8075 (MSFT)
- CIDR Block: 4.192.0.0/12
- Network Name: MSFT
- RIR: ARIN
Geolocation:
- Country: Singapore (SG)
- Coordinates: 1.35°N, 103.82°E
- Timezone: Asia/Singapore
- Geo Validation: Consensus verified (1 source)
Network Role:
- Infrastructure Type: CloudCompute
- Provider: Microsoft Azure
- Classification: Cloud Hosting
- Services: Firewalled / No Services detected
Risk Indicators:
- Overall Risk Score: 60/100
- Provider Score: 0
- Authority Score: 0
- DNSBL Listings: 1 of 8 lists
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
---
## THREAT OBSERVATION HISTORY
Observation Count: 30 signals recorded
Threat Persistence: 0 days (not persistently malicious)
Threat Observation Count: 1
Key Historical Signals:
- Multiple traceroute probes detected (30-hop traces, incomplete due to ICMP blocking)
- Blacklist verification checks performed (0 listings in current scan)
- Ownership verification stable (0 ownership changes)
- Operator score: Minimal (0.1304)
- DNSSEC valid: True
Risk Trend: Stable with no escalation in threat severity over observed period.
---
## RELATIONSHIP GRAPH
Related Entities: 8 relationships detected
- Type: Same Network (Microsoft MSFT network)
- No hostname associations found
- No certificate matches
- No external organization links
Analysis: Relationships are confined to Microsoft's internal network infrastructure. No lateral movement indicators to external entities.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 4.194.24.143/24
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 0
- Abuse Density: 0 (Clean)
- Classification: Clean
Neighbor Profile:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 4.194.24.129 | 25 | 50 |
Assessment: Neighborhood exhibits low abuse density with only one low-risk neighbor detected. No correlated malicious activity in the /24 subnet.
---
## ACTIONABLE INTELLIGENCE
SOC Analyst Recommendations:
1. Traffic Allowance: The IP is legitimate Microsoft Azure infrastructure. Allow traffic from this address for expected Azure service communications (RDP, HTTPS, Azure management APIs).
2. Monitoring Priority: Medium. The moderate risk score (60) combined with DNSBL listing warrants standard monitoring. No immediate blocking action required.
3. Firewall Rules: Standard allow rules for Microsoft Azure traffic patterns. No specific block recommendations.
4. Alert Thresholds: Monitor for unusual outbound connections or data exfiltration patterns from internal systems communicating with this IP.
Recommended Actions:
- Whitelist for Microsoft Azure service traffic
- Monitor for anomalous connection patterns
- Review DNSBL listing context (1 of 8 lists)
- No immediate containment required
---
## RISK ASSESSMENT
| Factor | Rating | Notes |
|---|---|---|
| Infrastructure Legitimacy | Low Risk | Microsoft Azure |
| Threat Indicators | Low Risk | No known campaigns or attacker signatures |
| Network Reputation | Moderate Risk | Single DNSBL listing, cloud hosting classification |
| Geographic Risk | Low Risk | Singapore data center |
| Lateral Threat Potential | Low Risk | Clean neighborhood, no threat siblings |
Overall Verdict: Legitimate Microsoft Azure cloud infrastructure endpoint with minimal threat indicators. No immediate defensive action required beyond standard Azure traffic monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
| Honeypot | Trap endpoint probes | 1 |
| Enumeration | Path/resource enumeration | 8 |
🏢 Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 4.192.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting — Infrastructure provider without advanced routing |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS8075 |
| Network Prefix | 4.192.0.0/12 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 22:52:28 UTC |
| Last Seen | 2026-09-02 20:51:21 UTC |
| Profile Built | 2026-09-02 20:55:30 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 4.194.24.143
Who owns the IP address 4.194.24.143?
4.194.24.143 is registered to Microsoft Corporation. The address falls within the 4.192.0.0/12 network block. Registration is held at ARIN.
Where is 4.194.24.143 located?
Geolocation data places 4.194.24.143 in Singapore, SG, Singapore. The local time zone is Asia/Singapore. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 4.194.24.143 malicious or safe?
4.194.24.143 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 4.194.24.143 a VPN, proxy, or data center address?
4.194.24.143 is classified as cloud infrastructure and hosting infrastructure based on network ownership and behavioural analysis.