# THREAT INTELLIGENCE BRIEFING
Target: 104.198.216.220/32
Classification: LOW RISK
Date: 2026-06-20
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP address 104.198.216.220 is a Google Cloud infrastructure endpoint associated with googleusercontent.com. The IP maintains a low-risk reputation profile (risk score: 25/100) with no active threat indicators. No malicious campaigns, known attackers, or spam source classifications were identified.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Organization** | Google LLC (ASN 396982) |
| **Infrastructure Type** | Cloud Compute (Google Cloud) |
| **Geolocation** | Council Bluffs, IA, US |
| **DNS Resolution** | 220.216.198.104.bc.googleusercontent.com |
| **Open Ports** | None detected (firewalled/no services) |
| **Network Role** | Cloud-hosted, CDN-enabled |
---
## THREAT INDICATORS
- Risk Score: 25 (Low Risk)
- Threat Indicators: None
- Blacklist Count: 0
- DNSBL Listings: 1 (minor)
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## NETWORK CONTEXT
Subnet: 104.198.216.220/24
- Abuse Density: 1/10 (Low)
- Classification: Mostly Clean
- Threat Siblings: 1
- Active Siblings: 1
- Total Siblings: 1
Control Plane:
- Route Stability: Stable
- DNSSEC Valid: Yes
- RPKI State: Verified
- Operator Score: 0.3478 (Basic)
---
## OBSERVATION HISTORY
Total Observations: 21 signals
Risk Trend: Stable (no escalation)
Persistence: No persistent malicious behavior detected
Key Signals:
- Subnet abuse density maintained at 1 across recent observations
- Geolocation data consistent (Council Bluffs, IA)
- Service scans show no open ports
- ICMP validation blocked (standard for cloud infrastructure)
---
## RELATIONSHIP GRAPH
Total Relationships: 66
- DNS Associations: Multiple records pointing to bc.googleusercontent.com
- Network Associations: GOOGLE-CLOUD network segments
- Same Network: Multiple Google Cloud infrastructure references
---
## RECOMMENDED ACTIONS
Security Action: Monitor
Firewall Rule: Allow (No blocking recommended)
Rationale: This is a legitimate Google Cloud infrastructure endpoint with no malicious indicators. The IP is used for legitimate cloud services (googleusercontent.com). No firewall rules recommended unless the organization has specific blocking policies for Google Cloud IPs.
---
## CONCLUSION
104.198.216.220 presents a minimal threat profile. It is a standard Google Cloud Compute endpoint with no evidence of malicious activity. No immediate action required. SOC teams should continue monitoring for any behavioral changes, but this IP should not be treated as malicious or suspicious.
Confidence Level: HIGH
Data Sources: IPDebrief, Google Cloud Infrastructure Registry, DNS Records, Network Scanning Data
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 220.216.198.104.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 220.216.198.104.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 46% | 1 | 5 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 29% | 10 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-24 18:39:32 UTC |
| Last Seen | 2026-06-29 00:18:48 UTC |
| Profile Built | 2026-06-29 06:21:37 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 29 |
Full dossier details are available via our API.