# IP Intelligence Briefing: 136.108.54.159
## Executive Summary
IP 136.108.54.159 is a Google Cloud infrastructure address located in North Charleston, South Carolina. The address presents a moderate risk profile (score 50) with no active services detected. Historical indicators suggest occasional threat association with no persistent malicious activity.
## Ownership and Infrastructure
- Organization: Google LLC
- ASN: AS396982 (GOOGL-2)
- CIDR Block: 136.107.0.0/16
- Infrastructure Type: Google Cloud Platform
- Geolocation: United States, South Carolina, North Charleston
## Network Classification
- Reputation: Moderate Risk
- Risk Score: 50/100
- Network Role: Cloud infrastructure with firewalled/no services
- Open Ports: None detected
- DNS Resolution: 159.54.108.136.bc.googleusercontent.com
- Email Authentication: SPF and DMARC records present
## Threat Assessment
Current Indicators:
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Proxy/VPN: No
- DNSBL Listings: 2 of 8 lists
Threat Signals:
- AlienVault OTX: 1 pulse detected
- Operator Score: 0.3478 (Basic classification)
- Historical Threat Observations: 1
- Threat Persistence: None detected
## Subnet Analysis
Neighborhood (136.108.54.0/24):
- Abuse Density: Low (1/256 IPs flagged)
- Classification: Mostly Clean
- Active Siblings: 1
- Threat Siblings: 1
- High Risk Neighbors: 0
## Historical Observations
Analysis of 25 signal observations reveals:
- Recent traceroute attempts (30-hop paths)
- Subnet-level threat assessments showing mostly clean classification
- No evidence of persistent malicious activity
- Ownership stability maintained with no recent changes
## Security Recommendations
Action: Monitor but no immediate blocking recommended.
Rationale:
1. Legitimate Google Cloud infrastructure with proper email authentication
2. No open services or active ports detected
3. Historical threat signals do not indicate persistent malicious behavior
4. Subnet shows low abuse density with minimal threat siblings
Suggested Actions:
- Allow inbound traffic (standard cloud infrastructure behavior)
- Monitor outbound connections from internal hosts
- Implement rate limiting if unusual connection patterns observed
- No firewall rules required at this time
## Conclusion
This IP address represents legitimate Google Cloud infrastructure with a moderate risk profile driven by historical data rather than current activity. The absence of open services, combined with proper email authentication and low neighborhood abuse density, suggests benign cloud hosting operations. SOC teams should monitor but not block this address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 136.107.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 159.54.108.136.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 159.54.108.136.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 22:21:44 UTC |
| Last Seen | 2026-08-12 22:48:31 UTC |
| Profile Built | 2026-08-12 22:57:13 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.