# IP INTELLIGENCE BRIEFING: 4.205.213.117/32
Classification: Microsoft Azure Cloud Infrastructure
Risk Assessment: Low Risk (Score: 25/100)
Report Date: 2026-06-16
---
## EXECUTIVE SUMMARY
IP 4.205.213.117 is a Microsoft Azure cloud infrastructure address with low-risk profile. The IP shows no active threat indicators, no blacklist presence, and no known malicious activity. Standard defensive posture recommended.
---
## OWNERSHIP AND INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | Microsoft Corporation |
| **ASN** | 8075 (MSFT) |
| **CIDR Block** | 4.192.0.0/12 |
| **RIR** | ARIN |
| **Infrastructure Type** | Microsoft Azure (Cloud) |
| **Connection Type** | Firewalled / No Services |
---
## GEOLOCATION
| Attribute | Value |
|---|---|
| **Country** | Canada (CA) |
| **Region** | Ontario (ON) |
| **City** | Toronto |
| **Coordinates** | 43.65°N, -79.38°W |
| **Timezone** | America/Toronto |
| **Accuracy Radius** | 150 km |
*Note: Geographic validation flags indicate geoPlausible: false. Multiple geolocation sources provide consensus data.*
---
## THREAT INTELLIGENCE
| Indicator | Status |
|---|---|
| **Abuse Confidence** | Null |
| **Is Tor Exit** | No |
| **Is Known Attacker** | No |
| **Is Spam Source** | No |
| **Blacklist Count** | 0 |
| **Threat Feeds** | None |
| **Known Campaigns** | None |
| **DNSBL Listed** | 1 of 8 lists |
Observation History: 16 signal observations recorded. Threat observation count: 1. Not persistently malicious.
---
## NETWORK BEHAVIOR
| Attribute | Value |
|---|---|
| **Open Ports** | None detected |
| **TLS Certificate** | None |
| **HTTP Title** | None |
| **Service Purpose** | Firewalled / No Services |
| **Honeypot Hits** | 0 |
| **Enumeration Strikes** | 0 |
| **WAF Violations** | 0 |
| **Total Incidents** | 0 |
---
## NEIGHBORHOOD ANALYSIS
| Attribute | Value |
|---|---|
| **Subnet** | 4.205.213.117/24 |
| **Abuse Density** | 1 |
| **Classification** | Mostly Clean |
| **Inherited Risk** | 2 |
| **Total Siblings** | 1 |
| **Active Siblings** | 0 |
| **Threat Siblings** | 1 |
---
## CONTROL PLANE
| Attribute | Value |
|---|---|
| **BGP Prefix** | 4.192.0.0/12 |
| **Origin ASN** | 8075 |
| **Route Stability** | Unstable (isRouteStable: false) |
| **Route Changes (30d)** | 0 |
| **RPKI State** | Not assessed |
| **DNSSEC Valid** | Yes |
| **Operator Score** | 0.1304 (Minimal) |
| **Hop Count** | 30 |
| **First Hop RTT** | 0.2 ms |
| **Last Hop RTT** | 35.3 ms |
| **Timed Out Hops** | 20 |
| **Transit Network** | Comcast |
---
## RELATIONSHIP GRAPH
| Type | Target |
|---|---|
| Same Network | MSFT |
---
## DNS ANALYSIS
| Attribute | Value |
|---|---|
| **PTR Hostnames** | None |
| **Forward Resolution** | Not confirmed |
| **Hosted Domains** | 0 |
| **SPF Record** | None |
| **DMARC Record** | None |
| **TXT Record Count** | 0 |
---
## SECURITY ACTIONS RECOMMENDATION
Risk Score: 25/100 โ Low Risk
Recommended Actions: None required. No firewall rules or blocking actions recommended based on current risk profile.
Note: IP represents standard Microsoft Azure cloud infrastructure with no active malicious indicators.
---
## ANALYST NOTES
1. Low-Risk Profile: IP 4.205.213.117 is a Microsoft Azure address with no active threat indicators, no blacklist presence, and zero incidents.
2. Cloud Infrastructure: Identified as Microsoft Azure provider (firewalled/no services). No open ports or services detected.
3. Neighborhood Context: Subnet shows abuse density of 1 with 1 threat sibling. Classification remains "mostly clean."
4. Monitoring: No specific monitoring required beyond standard cloud infrastructure baseline. No firewall rules recommended.
5. Historical Signals: 16 observations recorded with recent signals from 2026-06-16 showing ownership and routing information consistent with Microsoft infrastructure.
---
Status: Monitor | Priority: Low | Action: None Required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 4.192.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 17% | 1 | 1 |
| Overall | 25% | 8 | 12 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-11 15:08:48 UTC |
| Last Seen | 2026-06-21 19:03:15 UTC |
| Profile Built | 2026-06-21 19:05:29 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.