# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 162.216.150.220/32
Date: August 2026
Classification: Google Cloud Infrastructure
## EXECUTIVE SUMMARY
IP 162.216.150.220 is identified as legitimate Google Cloud Platform infrastructure with a risk score of 0. The address belongs to ASN 396982 (GOOGLE-CLOUD-PLATFORM) within the 162.216.148.0/22 CIDR block. While the primary IP shows minimal threat indicators, historical data reveals blacklist listings that warrant monitoring. No active services or open ports are currently detected.
## OWNERSHIP & INFRASTRUCTURE
- Organization: Google LLC
- Network Name: GOOGLE-CLOUD
- ASN: 396982
- CIDR Block: 162.216.148.0/22
- Geolocation: United States, North Charleston, SC (US)
- Infrastructure Type: CloudCompute (Google Cloud Platform)
- Network Classification: Cloud provider infrastructure
## THREAT ASSESSMENT
Risk Score: 0 (Low Risk)
Abuse Confidence Score: Not applicable
Blacklist Status: 8 total listings detected in historical data, including 1 high-severity listing observed 2026-08-06. Current active listings: 0.
Threat Indicators: None
Known Campaigns: None
Tor Exit/Proxy: False
## NETWORK BEHAVIOR
- Open Ports: None detected
- HTTP Services: None detected
- DNS Resolution: Forward resolution not confirmed
- PTR Hostnames: None
- TLS Certificates: None
The IP shows characteristics of a firewalled cloud infrastructure endpoint with no publicly accessible services.
## SUBNET CONTEXT (162.216.150.0/24)
- Total Neighbors: 78 IPs
- Abuse Density: 0
- Risk Distribution:
- High Risk: 0
- Medium Risk: 3
- Low Risk: 73
- Average Neighbor Risk Score: ~28 (based on sampled neighbors)
- Notable Neighbors: 162.216.150.3, .4, .5, .6 (risk score 25, authority score 90); 162.216.150.10 (risk score 50, authority score 90)
The subnet demonstrates typical cloud infrastructure patterns with low abuse density. Medium-risk neighbors appear to be legitimate cloud services with high authority scores.
## OBSERVATION HISTORY
- Total Observations: 13 signals recorded
- Latest Activity: 2026-08-06
- DNSSEC Status: Valid
- Key Historical Events:
- 2026-08-06: Blacklist listing detected (high severity, 8 total lists)
- 2026-08-06: DNSSEC validation confirmed
- 2026-08-06: ASN and geolocation signals consistent with Google Cloud
## RECOMMENDED ACTIONS
Current Risk Level: Low
Recommended Action: Monitor only; no immediate blocking required.
Firewall Rules: None required at this time.
SIEM Monitoring: Track blacklist listing activity in historical data. If the high-severity listing becomes active, investigate associated threat intelligence feeds.
## SOC ANALYST NOTES
This IP represents legitimate Google Cloud Platform infrastructure. The zero risk score and absence of active threat indicators indicate normal cloud service operation. The historical blacklist listing appears to be resolved (0 current listings). Continue routine monitoring of the /24 subnet for any changes in risk distribution. No escalation or investigation required absent new threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 162.216.148.0/22 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 220.150.216.162.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 220.150.216.162.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 28% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-02 23:10:00 UTC |
| Last Seen | 2026-08-13 04:12:36 UTC |
| Profile Built | 2026-08-13 04:26:38 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.