# IP Intelligence Briefing: 4.246.61.185
## Executive Summary
IP address 4.246.61.185 is a Microsoft Azure cloud infrastructure host classified as Moderate Risk (risk score: 50). The IP belongs to Microsoft Corporation (ASN 8075) and is located in the United States (Washington). While the subnet shows low abuse density and clean classification, the IP is listed on 2 out of 8 DNS blocklists and exposes SSH on port 22.
## Infrastructure Profile
- Organization: Microsoft Corporation
- ASN: AS8075
- Network Role: CloudCompute (Microsoft Azure)
- Geolocation: US, WA (Quincy)
- Infrastructure Type: Cloud hosting with single-service host purpose
- Classification: Cloud infrastructure, not residential, proxy, VPN, or Tor
## Threat Indicators
- Risk Score: 50 (Moderate Risk)
- DNSBL Status: Listed on 2 of 8 DNS blacklists
- Known Campaigns: None detected
- Threat Feeds: No active threat feed matches
- Abuse Confidence Score: Not calculated
- Known Attacker/Spam Source: Not flagged
- Tor Exit Node: No
## Network Services
- Open Ports: 22/TCP (SSH - OpenSSH_8.9p1 Ubuntu-3ubuntu0.15)
- TLS Certificates: None detected
- HTTP Services: None detected
- DNS Records: No reverse resolution, no hosted domains
## Observation History
Analysis of 20 recent observations reveals consistent Microsoft Azure cloud infrastructure classification. The IP has demonstrated stability in its network role classification with recent signals from June 2026. Operator score of 0.3478 indicates basic routing characteristics.
## Neighborhood Analysis
- Subnet: 4.246.61.0/24
- Abuse Density: 0 (low)
- Classification: Mostly clean
- Threat Siblings: 1
- Active Siblings: 1
- Total Siblings: 1
## Relationships
The IP shows 26 relationships, all categorized as "Same Network" pointing to Microsoft (MSFT), confirming this is part of Microsoft's corporate network infrastructure.
## Recommended Actions
Based on the risk profile and DNSBL listings, the following defensive measures are recommended:
| Platform | Action |
|---|---|
| **Firewall (iptables)** | `iptables -A INPUT -s 4.246.61.185 -j DROP` |
| **Firewall (nftables)** | `nft add rule inet filter input ip saddr 4.246.61.185 drop` |
| **Nginx** | `deny 4.246.61.185;` |
| **pfSense** | `4.246.61.185/32` |
| **Cloudflare WAF** | Block with expression `ip.src eq 4.246.61.185` |
| **AWS WAF** | `Addresses: ["4.246.61.185/32"]` |
## Analyst Notes
This IP presents a moderate risk profile due to DNSBL listings despite being part of Microsoft Azure infrastructure. The SSH service exposure on port 22 could indicate potential compromise or unauthorized access attempts. The 2 DNSBL listings suggest the IP may have been involved in prior malicious activity or has been associated with spam sources. Recommend blocking inbound traffic while monitoring for any outbound connections that might indicate active compromise. The subnet-level abuse density remains low, suggesting this is an isolated incident rather than broader subnet compromise.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | β |
| CIDR Block | 4.240.0.0/12 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 24% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 23% | 11 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 21:00:30 UTC |
| Last Seen | 2026-06-28 16:03:32 UTC |
| Profile Built | 2026-06-29 04:07:40 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.