# IP INTELLIGENCE BRIEFING: 104.199.205.178
## Executive Summary
IP address 104.199.205.178 is identified as legitimate Google Cloud infrastructure with a low-risk profile. No malicious indicators were detected across threat feeds, blacklist sources, or historical observations. Recommended classification: CLEAN with standard allow rules.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 104.199.205.178/32 |
| **Risk Score** | 25 (Low Risk) |
| **Organization** | Google LLC |
| **ASN** | 396982 |
| **RIR** | ARIN |
| **Infrastructure Type** | Cloud Compute (Google Cloud) |
| **Geolocation** | Changhua, Taiwan (TW) |
| **Coordinates** | 24.05°N, 120.55°E |
| **Timezone** | Asia/Taipei |
| **DNS Hostname** | 178.205.199.104.bc.googleusercontent.com |
---
## Threat Assessment
Threat Indicators:
- No threat feed matches
- Zero blacklist listings (0/8 DNSBL checks)
- Not associated with known campaigns
- No Tor exit node activity
- Not identified as spam source or known attacker
Network Classification:
- Cloud infrastructure: Yes
- CDN/Proxy/VPN: No
- Hosting service: Yes (Google Cloud platform)
- Mobile/Residential: No
---
## Neighborhood Analysis
Subnet: 104.199.205.178/24
- Abuse Density: 0 (Minimal)
- Classification: Mostly Clean
- Active Siblings: 2 (104.199.205.32)
- Sibling Risk Distribution: 1 low-risk, 0 medium/high-risk
- Neighborhood Risk: Score 5 (Low)
---
## Historical Observation Analysis
Total Observations: 28 signals tracked
- Recent Activity: Consistent Google Cloud infrastructure classification
- Geolocation Stability: Changhua, TW maintained across observations
- Threat Persistence: 0 days (no persistent malicious behavior)
- Threat Observation Count: 1 (minimal historical footprint)
- Is Persistently Malicious: No
---
## Relationship Graph
Total Relationships: 86
- Primary Association: Google Cloud network (GOOGLE-CLOUD)
- DNS Associations: googleusercontent.com hosted domains
- Network Classification: Same network relationships confirmed
- No Adverse Relationships: No connections to malicious entities detected
---
## Recommended Security Actions
| Action | Recommendation |
|---|---|
| **Firewall Rule** | Allow traffic (low risk, legitimate infrastructure) |
| **WAF Policy** | No blocking required |
| **Monitoring** | Standard monitoring (no special attention needed) |
| **Threat Intelligence** | No correlation to active campaigns |
Note: No specific firewall rules generated due to low-risk profile.
---
## SOC Analyst Guidance
Classification: LEGITIMATE INFRASTRUCTURE
Action: Monitor as normal cloud traffic
1. Allow Rules: Permissive rules appropriate for Google Cloud infrastructure
2. Monitoring: Standard network monitoring applies
3. Alerting: No specific alerting required
4. Investigation: No active investigation needed
Context: This IP represents legitimate Google Cloud Platform infrastructure in Taiwan. Traffic patterns consistent with CDN/hosting services. No malicious activity detected across threat intelligence sources.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | โ |
| CIDR Block | 104.199.192.0/20 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 178.205.199.104.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 178.205.199.104.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 58% | 2 | 15 |
| services | 12% | 2 | 2 |
| ownership | 24% | 3 | 4 |
| reputation | 30% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 33% | 12 | 32 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 08:57:14 UTC |
| Last Seen | 2026-06-27 19:01:09 UTC |
| Profile Built | 2026-06-28 13:07:00 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 45 |
Full dossier details are available via our API.