# THREAT INTELLIGENCE BRIEFING
Target IP: 162.216.149.149/32
Classification: LOW RISK β Google Cloud Infrastructure
Generated: 2026-06-20
---
## EXECUTIVE SUMMARY
IP 162.216.149.149 is a low-risk (score: 25/100) Google Cloud Platform address located in Moncks Corner, South Carolina. The IP demonstrates typical cloud infrastructure characteristics with no exposed services, no open ports, and no active threat indicators. Historical analysis shows occasional DNSBL listings but no persistent malicious behavior. The subnet (162.216.149.0/24) exhibits moderate abuse density with 21 threat siblings out of 46 total neighbors, but the target IP itself shows no malicious activity.
---
## OWNERSHIP & GEOSPATIAL
| Attribute | Value |
|---|---|
| Organization | Google LLC |
| ASN | 396982 (GOOGLE-CLOUD-PLATFORM) |
| Country | United States (US) |
| Region | South Carolina |
| City | Moncks Corner |
| RIR | ARIN |
| CIDR Block | 162.216.149.0/24 |
Control Plane: Route stable (isRouteStable: true), BGP prefix 162.216.149.0/24, operator score 0.5652 (Moderate), DNSSEC valid.
---
## NETWORK ROLE & CLASSIFICATION
- Infrastructure Type: Google Cloud Platform
- Cloud Provider: Yes
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Is CDN/Tor/Proxy/Hosting: No
DNS Resolution: 149.149.216.162.bc.googleusercontent.com (forward confirmed)
---
## THREAT ANALYSIS
| Indicator | Status |
|---|---|
| Reputation | Low Risk (Score: 25) |
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Blacklist Count | 0 |
| Known Campaigns | None |
| Threat Persistence | 0 days |
Historical Signals: 24 observations tracked. Notable DNSBL listing detected on 2026-06-15 (max severity: high), but no persistent malicious activity observed. Recent routing and ownership signals remain stable.
---
## NEIGHBORHOOD ASSESSMENT
Subnet: 162.216.149.0/24
- Total Siblings: 46
- Active Siblings: 28
- Threat Siblings: 21
- Abuse Density: 0.4565 (Moderate)
- Risk Classification: Mixed
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 19
- Low Risk: 34
Most neighbors show authority scores of 90, confirming Google Cloud infrastructure. No high-risk neighbors detected in immediate vicinity.
---
## RELATIONSHIP GRAPH
| Type | Target |
|---|---|
| Same Network | GOOGLE-CLOUD |
| DNS Association | 149.149.216.162.bc.googleusercontent.com |
---
## RECOMMENDATIONS
Action: No blocking required. IP is legitimate Google Cloud infrastructure with no active threat indicators.
Firewall Policy: Allow standard Google Cloud egress/ingress patterns. No specific firewall rules recommended.
Monitoring: No enhanced monitoring required. Standard cloud provider traffic patterns expected.
IOC Status: No IOCs generated. No campaign correlations detected.
---
Analyst Notes: This IP represents normal Google Cloud Platform usage. The historical DNSBL listing from mid-June appears to be a transient event unrelated to the target IP's current activity. The subnet's moderate abuse density is consistent with mixed-use Google Cloud infrastructure. No defensive action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | 162.216.149.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 149.149.216.162.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 149.149.216.162.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 56% | 2 | 12 |
| services | 12% | 2 | 2 |
| ownership | 27% | 3 | 4 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 30% | 12 | 27 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-16 08:56:08 UTC |
| Last Seen | 2026-06-28 03:17:28 UTC |
| Profile Built | 2026-06-28 21:22:27 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 36 |
Full dossier details are available via our API.