# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 136.66.201.95/32
Classification: LOW RISK - GOOGLE CLOUD INFRASTRUCTURE
Report Date: 2026-08-05
---
## EXECUTIVE SUMMARY
The IP address 136.66.201.95 operates as legitimate Google Cloud infrastructure with zero malicious indicators. All threat intelligence signals indicate clean, trusted hosting services. No defensive action required.
---
## OWNERSHIP & NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| **Organization** | Google LLC (GOOGL-2) |
| **ASN** | 396982 |
| **CIDR Block** | 136.64.0.0/11 |
| **RIR** | ARIN |
| **Geolocation** | US, Oregon (The Dalles) |
| **Coordinates** | 45.6°N, 121.18°W |
| **Timezone** | America/Los_Angeles |
---
## THREAT INTELLIGENCE ASSESSMENT
Risk Score: 0/100
Reputation: Low Risk
Abuse Confidence: None
Blacklist Status: Not listed (0/0 lists)
Threat Indicators:
- Not a Tor exit node
- Not a known attacker
- Not a spam source
- No threat feeds correlations
- No known campaign associations
Network Classification:
- Provider: Google Cloud
- Infrastructure Type: CloudCompute
- Connection Type: Hosting
- Cloud Platform: Yes
- CDN/VPN/Proxy: No
---
## SERVICE & PORT ANALYSIS
Open Ports:
- TCP/443 (HTTPS) - Active
TLS Certificate:
- Issuer: CN=91ffaeab-05f8-458e-8ed9-33182c7019b4
- Subject: CN=34.177.118.107
- SANs: kubernetes, kubernetes.default, kubernetes.default.svc, kubernetes.default.svc.cluster.local
- Status: Valid, self-signed: false
DNS Records:
- PTR Hostname: 95.201.66.136.bc.googleusercontent.com
- Forward Resolution: Confirmed (1 record)
- Email Auth: SPF and DMARC configured
---
## OBSERVATION HISTORY (24 Signals)
Recent Activity Window: 2026-08-05
Key Observations:
- TLS certificate scans: Multiple observations
- Geolocation inference: US, Oregon (confidence 0.56)
- ASN attribution: Google LLC (confidence 0.85)
- DNS records: cluster.local domain detected
- Blacklist monitoring: 0/8 lists, max severity null
Temporal Analysis:
- Ownership changes: 0
- Threat persistence: 0 days
- Threat observation count: 0
- Persistently malicious: No
---
## RELATIONSHIP GRAPH (15 Relationships)
DNS Associations:
- 95.201.66.136.bc.googleusercontent.com (repeated 9x)
Network Associations:
- GOOGL-2 (repeated 6x)
Relationship Type: Cloud infrastructure with consistent DNS and network topology patterns typical of Google Cloud Platform services.
---
## NEIGHBORHOOD ANALYSIS (136.66.201.0/24)
Subnet Classification: Clean
Abuse Density: 0
Risk Distribution: High: 0, Medium: 0, Low: 0
Active Siblings: 1 (target IP)
Threat Siblings: 0
No adjacent IPs show malicious behavior; subnet is classified as clean infrastructure.
---
## RECOMMENDED ACTIONS
Status: No Action Required
Firewall Rules: None recommended
WAF Configuration: No specific rules needed
Block Decision: Do not block
Rationale: This IP is confirmed Google Cloud infrastructure with zero threat indicators, no blacklist presence, and clean neighborhood analysis. Blocking would disrupt legitimate cloud services.
---
## CONCLUSION
IP 136.66.201.95 represents standard Google Cloud Platform hosting infrastructure located in Oregon, USA. All signals indicate legitimate operation with no malicious activity, threat associations, or reputation concerns. Continue monitoring as part of routine cloud infrastructure operations. No defensive action warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 136.64.0.0/11 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 95.201.66.136.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 95.201.66.136.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-21 19:02:45 UTC |
| Last Seen | 2026-08-12 16:08:15 UTC |
| Profile Built | 2026-08-12 16:21:25 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.