# IP Intelligence Briefing: 136.108.90.156/32
## Executive Summary
IP address 136.108.90.156 is registered to Google LLC (ASN 396982) and operates within the GOOGL-2 network (136.107.0.0/16). The IP carries a moderate risk score of 50 with 2 DNSBL listings. Geolocation data indicates South Carolina, US, but RTT analysis flags a 6,958 km distance violation, suggesting unreliable location data. No active threat campaigns or known attacker indicators are present.
## Threat Assessment
Risk Profile: Moderate Risk (Score: 50)
- Threat Indicators: None detected; 0 known attacker flags, 0 spam source flags, 0 Tor exit node flags
- Abuse Signals: 2 DNSBL listings out of 8 total lists; 0 blacklist entries in threat feeds
- Campaign Correlation: 0 certificate matches, 0 correlated IPs, 0 campaign associations
- Persistence: Single threat observation recorded; not persistently malicious
Network Classification:
- Provider: Google Cloud
- Infrastructure Type: Single-Service Host
- Connection Type: Unknown
- Control Plane: Route stable, DNSSEC valid, CAA record present
- Operator Score: 0.3478 (Basic)
## Service Exposure
- Port 22/TCP: Open (SSH-2.0-OpenSSH_10.0)
- DNS Resolution: 156.90.108.136.bc.googleusercontent.com
- Email Authentication: SPF and DMARC records present
- TLS Certificate: None observed
- HTTP Services: No web services detected
## Neighborhood Analysis
- Subnet: 136.108.90.156/24
- Abuse Density: 0.0 (clean)
- Active Siblings: 0
- Threat Siblings: 0
- Neighbor Count: 1 (136.108.90.100)
## Historical Observations
Total of 26 observations recorded. Most recent activity detected on 2026-08-05. Signal types include geolocation traces, ownership verification, and threat correlation events. No persistent malicious behavior pattern observed.
## Recommended Actions
The following firewall rules have been generated based on the IP's risk profile:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 136.108.90.156 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 136.108.90.156 drop` |
| nginx | `deny 136.108.90.156;` |
| pfSense | `136.108.90.156/32` |
| Cloudflare WAF | Block IP with description "IPDebrief risk score 50" |
| AWS WAF | Block address 136.108.90.156/32 |
## Analyst Notes
This IP belongs to Google Cloud infrastructure. While the moderate risk score and presence of open SSH suggest caution, the clean neighborhood profile and lack of campaign associations indicate this may be legitimate cloud infrastructure. The geolocation discrepancy (6,958 km with RTT violation) should be considered when evaluating the South Carolina location data. SOC teams should evaluate the open SSH port in context of their threat environment before implementing blocking rules.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 136.107.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 156.90.108.136.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 156.90.108.136.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 1/4 domains |
| DMARC | 1/4 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 4 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | kuberneteskubernetes.defaultkubernetes.default.svckubernetes.default.svc.cluster.local |
| Valid From | 2026-08-12T19:02:59+00:00 |
| Valid Until | 2027-08-12T19:04:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 023FC0C5FCA47E47BAB70CBDF853714D |
| Thumbprint | 0AB6A434657FF8BEBE68A582737AE36A32FAEF67 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 27% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 22:21:44 UTC |
| Last Seen | 2026-08-12 22:48:41 UTC |
| Profile Built | 2026-08-12 23:03:41 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 29 |
Full dossier details are available via our API.