# IP Intelligence Briefing: 4.223.126.210/32
## Executive Summary
Target 4.223.126.210 is a Microsoft Azure cloud infrastructure IP (AS8075) located in Stockholm, Sweden. The IP presents a low risk profile with a risk score of 25/100. No active threat indicators detected in current profile, though historical signals indicate intermittent threat activity.
## Infrastructure Profile
- Organization: Microsoft Corporation (MSFT)
- ASN: 8075
- Network Block: 4.208.0.0/12
- Geolocation: Stockholm, Sweden (59.33°N, 18.07°E)
- Infrastructure Type: CloudCompute (Azure)
- Current Status: Firewalled / No Services Open
- DNSSEC: Valid
## Threat Assessment
Current Risk Level: LOW (25/100)
- Blacklist Status: Not currently listed on threat feeds
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Active Threat Indicators: None in current profile
Historical Observations: Signal history indicates intermittent threat activity with 8 blacklist listings at one point (high severity). Geographic signals consistently placed in Stockholm, Sweden.
## Neighborhood Analysis
- Subnet: 4.223.126.210/24
- Abuse Density: 0 (Clean)
- Threat Siblings: 0
- Neighboring IPs: None detected
## Behavioral Characteristics
- Route Stability: Unstable (route changes observed in 30-day period)
- Honeypot Hits: 0
- Enumeration Strikes: 0
- Persistence Days: 0 (not persistently malicious)
## Related Entities
- Network Relationships: 9 connections to MSFT network infrastructure
- Campaign Correlation: None detected
## Recommended Actions
Priority: LOW
Given the low-risk classification and Microsoft Azure infrastructure ownership, standard monitoring is recommended:
1. Allow with logging: Permissive firewall rules with log capture for forensic analysis
2. Monitor for behavioral anomalies: Track for unexpected service exposure or traffic patterns
3. Geographic validation: Verify Stockholm location consistency during connection attempts
## SOC Analyst Notes
This IP represents legitimate cloud infrastructure. The historical threat signals appear to be transient rather than indicative of persistent malicious activity. No immediate blocking required. Recommend continued monitoring for any changes in service exposure or traffic patterns inconsistent with cloud infrastructure behavior.
---
*Intelligence generated from IPDebrief analysis tools. Data current as of analysis timestamp.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 4.208.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting — Infrastructure provider without advanced routing |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS8075 |
| Network Prefix | 4.208.0.0/12 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 8 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 22% | 1 | 4 |
| geolocation | 17% | 2 | 3 |
| Overall | 19% | 10 | 21 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 23:22:23 UTC |
| Last Seen | 2026-09-14 00:09:56 UTC |
| Profile Built | 2026-09-14 01:00:17 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 30 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 4.223.126.210
Who owns the IP address 4.223.126.210?
4.223.126.210 is registered to Microsoft Corporation. The address falls within the 4.208.0.0/12 network block. Registration is held at ARIN.
Where is 4.223.126.210 located?
Geolocation data places 4.223.126.210 in Stockholm, AB, Sweden. The local time zone is Europe/Stockholm. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 4.223.126.210 malicious or safe?
4.223.126.210 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
Is 4.223.126.210 a VPN, proxy, or data center address?
4.223.126.210 is classified as cloud infrastructure and hosting infrastructure based on network ownership and behavioural analysis.