# IP Intelligence Briefing: 104.199.233.22
## Executive Summary
Risk Assessment: LOW RISK (Score: 25/100) โ This IP address is a legitimate Google Cloud Platform infrastructure endpoint with no active threat indicators. No blocking or defensive action required.
---
## Infrastructure Profile
Ownership & Provider:
- Organization: Google LLC (ASN 396982)
- Network: Google Cloud Platform
- Infrastructure Type: Cloud Compute
- CIDR Block: 104.199.224.0/20
- RIR: ARIN (Registration: 2014-08-27)
Geolocation:
- Country: Taiwan (TW) โ Changhua
- Coordinates: 24.05°N, 120.55°E
- Note: Geo-validation shows ICMP blocking; 9,348km distance from probe location
DNS Resolution:
- PTR Hostname: 22.233.199.104.bc.googleusercontent.com
- Forward Resolution: 22.233.199.104.bc.googleusercontent.com
- DNSSEC: Valid
- SPF/DMARC: Configured (hasSPF: true, hasDMARC: true)
Services:
- Open Ports: None detected
- Connection Status: Firewalled / No Services
- TLS Certificate: None observed
---
## Threat Intelligence
Threat Indicators:
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listings: 1/8 total lists
- Known Campaigns: None
- Abuse Confidence Score: Not calculated
Campaign Analysis:
- Campaign Likelihood: None
- CERT Matches: 0
- Correlated IPs: 0
Control Plane:
- Origin ASN: 396982 (Google LLC)
- BGP Prefix: 104.199.224.0/20
- Route Stability: Flagged as not stable
- RPKI State: Not available
- DNSSEC: Valid
- Operator Score: 0.3478 (Basic)
---
## Observation History
Signal Timeline: 22 observations recorded
Key Historical Signals:
- ASN consistency: Google Cloud (396982) maintained across all observations
- Prefix variations: 104.199.224.0/20 and 104.199.224.0/19 observed
- Geo-location: Consistently resolves to Taiwan region
- Operator classification: "Basic" across all measurements
- No persistent malicious activity detected
- Threat observation count: 1 (single historical signal)
---
## Network Neighborhood
Subnet Analysis (104.199.233.0/24):
- Abuse Density: 1 (low)
- Classification: mostly_clean
- Threat Siblings: 1
- Inherited Risk: 2/100
Relationships:
- 71 total relationships identified
- Primary associations: DNS hostnames (bc.googleusercontent.com), same network (GOOGLE-CLOUD)
- No malicious peer relationships detected
---
## Recommended Actions
Current Status: No action required
Firewall Rules: None recommended (low-risk infrastructure)
Monitoring Notes:
- IP is legitimate cloud infrastructure; normal traffic patterns expected
- No evidence of abuse, scanning, or malicious activity
- Consider whitelisting if this is expected Google Cloud traffic
- Monitor for any changes in risk profile
---
## Analyst Notes
This IP address represents standard Google Cloud Platform infrastructure. The low risk score, absence of threat indicators, and consistent Google Cloud ASN attribution confirm benign infrastructure status. The single DNSBL listing appears to be a false positive or minimal reputation flag unrelated to active threats. No defensive measures required.
Classification: INFRASTRUCTURE / LOW RISK
Last Updated: Based on current data
Recommendation: Allow / Monitor only
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 22.233.199.104.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 22.233.199.104.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 5 |
| routing | 42% | 1 | 8 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 29% | 10 | 24 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-13 12:03:55 UTC |
| Last Seen | 2026-06-27 23:00:45 UTC |
| Profile Built | 2026-06-28 17:06:16 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 35 |
Full dossier details are available via our API.