# IP Intelligence Briefing: 4.224.61.94/32
## Executive Summary
IP 4.224.61.94 belongs to Microsoft Corporation (MSFT) within the 4.224.0.0/12 CIDR block. Risk assessment indicates LOW RISK with a risk score of 0. The IP is classified as firewalled with no open services or ports, consistent with Microsoft Azure infrastructure. No threat indicators, blacklist entries, or malicious activity have been observed.
## Ownership & Network Classification
- Organization: Microsoft Corporation
- ASN: Not assigned (enterprise-managed)
- CIDR Block: 4.224.0.0/12
- RIR: ARIN
- Provider Score: 0
- Authority Score: 0
- Classification: Enterprise/Cloud Infrastructure (Microsoft Azure)
## Geolocation Analysis
- Primary Location: India (Maharashtra, Pune)
- Coordinates: 18.52°N, 73.85°E
- Timezone: Asia/Kolkata
- Geo Sources: 1 source with consensus validation
- Note: Microsoft maintains global data centers; location variance may reflect distributed infrastructure or CDN edge placement
## Threat Assessment
- Risk Score: 0 (Low Risk)
- Abuse Confidence Score: N/A
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Indicators: None
- Known Campaigns: None
- Behavioral Flags: No honeypot hits, no enumeration strikes, no WAF violations
## Network Services & DNS
- Open Ports: None detected
- DNS Resolution: No PTR records; forward resolution failed
- Hosted Domains: 0
- Email Authentication: No SPF/DMARC records
- Service Purpose: Firewalled / No Services
- HTTP/TLS: No active web services or certificates
## Neighborhood Analysis
- Subnet: 4.224.61.94/24
- Abuse Density: 0
- Neighbor Count: 0
- Threat Siblings: 0
- High/Medium Risk Neighbors: 0
## Observation History (6 Observations)
Recent signal activity (2026-08-06):
- Ownership Signals: Confirmed Microsoft Corporation with 95% confidence
- Geolocation Signals: India (Pune) at 70% confidence; additional US-based signals observed (Washington, 98052)
- Threat Signals: Minimal signals detected with low confidence scores (0.08-0.30)
- Stability: No ownership changes; threat observation count: 0
## Relationships
- Same Network: MSFT (Microsoft)
- Related Entities: 1 network-level relationship identified
## Recommended Actions
- Firewall Rules: None required (low risk)
- Monitoring: Standard logging recommended for baseline traffic
- Allow/Block: No action required; legitimate Microsoft infrastructure
- WAF/Cloudflare: No rules necessary
## Intelligence Assessment
This IP address represents legitimate Microsoft Corporation infrastructure, likely Azure cloud services or related enterprise networks. The absence of open ports, zero threat indicators, and clean reputation across all feeds confirm benign status. The India geolocation aligns with Microsoft's global presence. No defensive action required; standard enterprise traffic handling applies.
Classification: Legitimate Infrastructure / Low Risk
Recommended Treatment: Allow traffic with standard enterprise logging
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 4.224.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 21% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 30% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-01 10:25:23 UTC |
| Last Seen | 2026-08-13 12:53:32 UTC |
| Profile Built | 2026-08-13 02:50:11 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.