Intelligence analysis identified 142.250.31.119 as a Google LLC cloud compute host within the 142.250.0.0/15 block. The infrastructure resolved to the hostname bj-in-f119.1e100.net and responded to HTTP and HTTPS requests with a "gws" server banner. Risk assessment assigned a score of 25, categorizing the address as low risk.
Operational data indicated the endpoint appeared on one of eight DNS blocklists, yet the surrounding neighborhood classification remained clean with zero abuse density. Control plane metrics showed route instability. Threat actor classification flagged the host as suspicious; however, behavioral logs showed no active attacks, honeypot interactions, or enumeration strikes.
Technical inspection revealed TLS certificate validation failures with an issuer labeled "invalid2.invalid." The recommendation was to monitor the traffic due to low severity and the clean neighborhood context. No immediate threat indicators were confirmed despite the suspicious host tag.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS15169 |
| Network Name | |
| CIDR Block | 142.250.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | bj-in-f119.1e100.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | bj-in-f119.1e100.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | gws |
| HTTP Title | β |
π TLS Certificate
| SANs | invalid2.invalid |
| Valid From | 2026-08-10T09:42:20+00:00 |
| Valid Until | 2026-11-02T09:42:19+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 83 days |
| Serial Number | 0A0192130865F4876CD88E4C2FC591 |
| Thumbprint | AF3BC8F83CFF426D599E24002419EC614AC33EBF |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-15 22:30:49 UTC |
| Last Seen | 2026-09-15 22:30:49 UTC |
| Profile Built | 2026-09-15 22:48:22 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.