IPDEBRIEF INTELLIGENCE BRIEFING
Target: 162.216.149.103/32
Classification: Low Risk / Cloud Infrastructure
Generated: Current
---
EXECUTIVE SUMMARY
IP 162.216.149.103 is a low-risk (score: 25) cloud compute endpoint operated by Google LLC within the Google Cloud network. The IP resolves to Google Cloud infrastructure with no active threat indicators. No immediate blocking is recommended; standard cloud egress monitoring applies.
---
OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | Google LLC |
| **ASN** | 396982 |
| **CIDR Block** | 162.216.148.0/22 |
| **Network Name** | GOOGLE-CLOUD |
| **Infrastructure Type** | CloudCompute |
| **Service Purpose** | Firewalled / No Services |
The IP is hosted on Google Cloud infrastructure with no exposed services or open ports detected. DNS resolves to `103.149.216.162.bc.googleusercontent.com`, confirming legitimate cloud usage patterns.
---
GEOLOCATION
| Attribute | Value |
|---|---|
| **Country** | United States (US) |
| **Region** | South Carolina (SC) |
| **City** | Moncks Corner |
| **Coordinates** | 33.21°N, -80.17°W |
| **Timezone** | America/New_York |
---
THREAT ASSESSMENT
Current Risk Profile:
- Overall Risk Score: 25/100 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: 0/0 lists (clean)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
Control Plane Indicators:
- DNSBL Listed: 1/8 total lists
- Route Stability: Unstable
- RPKI State: Not reported
---
OBSERVATION HISTORY
Total Signals Observed: 18
Recent Activity (2026-07-30):
- Ownership confirmation: Google LLC (confidence: 0.95)
- Geolocation signals: US/SC, Moncks Corner (confidence: 0.56)
- One high-severity blacklist listing detected (max severity: high)
- No persistent malicious activity observed
Temporal Indicators:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
---
NEIGHBORHOOD ANALYSIS
Subnet: 162.216.149.0/24
| Metric | Value |
|---|---|
| **Total Siblings** | 78 |
| **Active Siblings** | 68 |
| **Threat Siblings** | 14 |
| **Abuse Density** | 0.1795 |
| **Classification** | Mostly Clean |
| **Inherited Risk** | 7/100 |
Risk Distribution in /24:
- High Risk: 0
- Medium Risk: 2
- Low Risk: 75
The subnet shows low abuse density with minimal malicious activity. The target IP inherits low risk from its network context.
---
RELATIONSHIP GRAPH
Active Relationships (5):
1. DNS Association: `103.149.216.162.bc.googleusercontent.com`
2. Same Network: GOOGLE-CLOUD
3. DNS Association: `103.149.216.162.bc.googleusercontent.com`
4. Same Network: GOOGLE-CLOUD
No certificate-based relationships detected.
---
RECOMMENDED ACTIONS
Firewall/Security Actions: None required at current risk level.
SOC Analyst Guidance:
- Treat as legitimate Google Cloud egress traffic
- No blocking or rate limiting recommended
- Monitor for any changes in behavior patterns
- Standard cloud infrastructure baseline applies
---
CONCLUSION
IP 162.216.149.103 is a legitimate Google Cloud infrastructure endpoint with low risk indicators. The subnet environment is clean with minimal threat presence. No defensive action is required beyond standard cloud traffic monitoring.
Priority: LOW
Recommendation: Allow / Monitor
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 162.216.148.0/22 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 103.149.216.162.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 103.149.216.162.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 42% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 14:52:40 UTC |
| Last Seen | 2026-08-12 19:41:09 UTC |
| Profile Built | 2026-08-12 20:09:56 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 39 |
Full dossier details are available via our API.