# IP Intelligence Briefing: 136.117.171.223/32
## Executive Summary
IP 136.117.171.223 is a low-risk infrastructure address belonging to Google LLC. The address operates as a web server within Google Cloud infrastructure and presents no immediate threat indicators. Current risk assessment: Low Risk (Score: 25/100).
## Ownership and Network Classification
- Organization: Google LLC
- ASN: 396982 (GOOGL-46)
- CIDR Block: 136.112.0.0/12
- RIR: ARIN
- Geolocation: The Dalles, Oregon, United States (45.6°N, -121.18°W)
- Infrastructure Type: Google Cloud Platform
- Connection Type: Web Server
## Threat Assessment
- Overall Risk Score: 25 (Low Risk)
- Blacklist Count: 0
- Known Attacker: False
- Tor Exit Node: False
- Known Campaigns: None
- Abuse Confidence Score: Not applicable
- DNSBL Listings: 1 of 8 total lists (dnsblListedCount)
## Service and Port Analysis
- Open Ports: 443/TCP (HTTPS)
- Protocol: HTTP/2 enabled
- TLS Version: TLS 1.3
- Cipher Suite: TLS_AES_128_GCM_SHA256
- HTTP Status Code: 403 (Forbidden)
- PTR Record: 223.171.117.136.bc.googleusercontent.com
- Forward Resolution: googleusercontent.com
## DNS and Certificate Information
- Domain: googleusercontent.com
- DNS Records: Forward confirmed
- TLS Issuer: CN=27ef6b88-48a9-4218-863c-f05456d1b8d7
- TLS Subject: CN=35.230.63.209
- Certificate: Self-signed: False
- Email Authentication: SPF: Present, DMARC: Present
## Observation History
The IP has generated 18 observations since last update (2026-06-16). Historical analysis reveals:
- No persistent malicious activity detected
- Threat observation count: 0
- Ownership changes: 0
- Average ownership days: Not applicable
- Network classification: Consistently marked as "clean"
Recent signals indicate standard Google Cloud HTTPS service behavior with 403 responses, typical for rate-limited or unauthorized access attempts to Google Cloud infrastructure.
## Neighborhood Analysis
- Subnet: 136.171.117.0/24
- Abuse Density: 0 (Clean)
- Threat Siblings: 0
- Total Siblings: 1
- Active Siblings: 0
- Classification: Clean
No neighboring IPs in the /24 subnet present threat indicators, indicating this is isolated infrastructure without associated malicious activity.
## Relationship Graph
- DNS Associations: Multiple associations to 223.171.117.136.bc.googleusercontent.com
- Network Relations: GOOGL-46 network (136.117.171.223/24)
- External Links: No malicious relationships detected
## Recommended Actions
- Risk Level: Low
- Firewall Recommendations: None required
- Monitoring Level: Standard monitoring appropriate
- Block Decision: No action recommended; this is legitimate Google Cloud infrastructure
## Conclusion
IP 136.117.171.223 is confirmed Google Cloud infrastructure with no malicious indicators. The 403 response code is consistent with legitimate web server behavior and does not indicate compromise. No firewall rules or blocking actions are recommended. Standard monitoring protocols apply.
---
*Report generated: 2026-06-16 | Data Source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-46 |
| CIDR Block | 136.112.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 223.171.117.136.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 223.171.117.136.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | kuberneteskubernetes.defaultkubernetes.default.svckubernetes.default.svc.cluster.local |
| Valid From | 2026-06-09T02:55:41+00:00 |
| Valid Until | 2027-06-09T02:57:41+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 602C6BA323D4A90A985ADBE0EDEDBA22 |
| Thumbprint | E75F58240FDDFA434A7BFF906EDEB284B6F911F1 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 24% | 2 | 2 |
| Overall | 25% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-07 19:58:03 UTC |
| Last Seen | 2026-06-21 14:07:16 UTC |
| Profile Built | 2026-06-21 14:11:48 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.