# IP Intelligence Briefing: 4.206.92.183/32
Classification: Microsoft Azure Cloud Infrastructure
Risk Assessment: Moderate Risk (65/100)
Date: Current Analysis Cycle
---
## Executive Summary
IP address 4.206.92.183 is an Azure-hosted Microsoft Corporation cloud resource located in Toronto, Ontario. The IP demonstrates moderate risk characteristics with 3 DNSBL listings across 8 total lists, though the immediate neighborhood shows no abuse activity. Recommended action: increase monitoring and evaluate against business context before blocking.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 65/100 (Moderate) |
| **Organization** | Microsoft Corporation (AS8075) |
| **Network** | 4.206.92.183/24 |
| **Location** | Toronto, Ontario, US |
| **Infrastructure** | Microsoft Azure (CloudCompute) |
| **Open Ports** | TCP/22 (SSH - OpenSSH 9.2p1 Debian) |
| **DNSBL Status** | Listed on 3 of 8 blacklists |
| **Operator Score** | 0.2174 (Minimal) |
---
## Threat Indicators
- Abuse Confidence: Not explicitly scored
- Campaign Association: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Proxy Service: No
The IP shows evidence of DNSBL listing activity with high-severity classifications observed in historical signals. No active threat campaigns or correlated malicious IPs identified.
---
## Neighborhood Analysis
Subnet 4.206.92.183/24 demonstrates clean characteristics:
- Abuse Density: 0
- Risk Distribution: No high or medium risk siblings
- Classification: Mostly clean
- Active Siblings: 1
- Threat Siblings: 1
The neighborhood context supports a legitimate cloud infrastructure assignment.
---
## Historical Signals
22 observations recorded, with key temporal patterns:
- Recent Classification: Cloud infrastructure (Microsoft Azure) consistently identified
- DNSBL Activity: Multiple listings observed with high-severity classifications
- Provider Stability: Consistent Microsoft Azure assignment
- Signal Count: 1 threat observation recorded
---
## Relationship Graph
43 relationships identified, all indicating same-network connections to Microsoft (MSFT). No external organizational or domain relationships detected beyond the Microsoft ecosystem.
---
## Recommended Actions
Immediate:
1. Increase logging verbosity for this IP and review recent activity patterns
2. Evaluate DNSBL listings to determine if they contribute to the moderate risk score
Firewall/Blocking:
- iptables: `iptables -A INPUT -s 4.206.92.183 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 4.206.92.183 drop`
- nginx: `deny 4.206.92.183;`
- Cloudflare WAF: Block with expression `ip.src eq 4.206.92.183`
- AWS WAF: Add IP 4.206.92.183/32 to block list
Decision Context:
Given the Microsoft Azure infrastructure classification and clean neighborhood profile, blocking should be evaluated against specific threat intelligence. The DNSBL listings warrant investigation to determine if they correlate with actual abuse activity or are false positives from cloud infrastructure misconfiguration.
---
Status: Monitor with elevated logging. Review DNSBL listings and correlate with internal threat detection systems before implementing blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-13 12:13:19 UTC |
| Last Seen | 2026-06-27 23:23:15 UTC |
| Profile Built | 2026-06-28 17:29:05 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.