# IP Intelligence Briefing: 34.118.112.245/32
## Executive Summary
IP address 34.118.112.245 is a Google Cloud infrastructure address with a moderate risk score of 50/100. The asset is geolocated to Warsaw, Poland, but exhibits geolocation inconsistencies with historical data also reporting United States. The IP maintains active SSH service exposure and is listed on two DNSBL feeds. Neighborhood analysis indicates zero abuse density within the /24 subnet.
## Ownership and Network Classification
- Organization: Google LLC (AS396982)
- Network Block: 34.64.0.0/10 (GOOGL-2)
- Network Role: Cloud Provider Infrastructure
- Infrastructure Type: Google Cloud Platform
- BGP Prefix: 34.118.112.0/20
- Route Stability: Unstable (isRouteStable: false)
## Geolocation
- Current Location: Warsaw, Mazovia, Poland (PL)
- Alternative Historical Location: United States (Kansas region)
- Geolocation Consensus: Mixed signals across multiple sources
- Accuracy Radius: 2,500 km
- DNS PTR Hostname: 245.112.118.34.bc.googleusercontent.com
## Threat Indicators
- Risk Score: 50 (Moderate Risk)
- DNSBL Listings: 2 of 8 total lists
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not reported
## Service Exposure
- Open Ports: TCP/22 (SSH)
- SSH Banner: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16
- TLS Certificate: Not present
- HTTP Title: Not present
- Certificate Authority Records: Present (hasCAA: true)
## Observational History
Analysis of 15 signal observations reveals consistent Google LLC ownership attribution across all data points. Geolocation signals show variance between Poland and United States reporting. Service scanning confirms SSH service exposure. No persistent malicious activity patterns detected; threat persistence days: 0.
## Related Entities
- DNS Associations: 245.112.118.34.bc.googleusercontent.com (repeated association)
- Network Relationship: GOOGL-2 network block
- Certificate Matches: 0
- Correlated IPs: 0
## Neighborhood Analysis
- Subnet: 34.118.112.245/24
- Abuse Density: 0 (no sibling IPs identified)
- High-Risk Siblings: 0
- Medium-Risk Siblings: 0
- Low-Risk Siblings: 0
- Threat Siblings: 0
## Recommended Security Actions
Given the moderate risk profile (50/100) and DNSBL listings, the following defensive measures are recommended:
| Platform | Action |
|---|---|
| iptables | `iptables -A INPUT -s 34.118.112.245 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 34.118.112.245 drop` |
| nginx | `deny 34.118.112.245;` |
| pfSense | `34.118.112.245/32` (block rule) |
| Cloudflare WAF | Block with expression `ip.src eq 34.118.112.245` |
| AWS WAF | Block address `34.118.112.245/32` |
Note: These recommendations are probabilistic and should be combined with additional threat intelligence signals before implementing blocking actions.
## Intelligence Assessment
The IP 34.118.112.245 represents Google Cloud infrastructure with moderate risk characteristics. While the asset is not associated with known campaigns or persistent malicious activity, the presence of DNSBL listings and inconsistent geolocation reporting warrants monitoring. The SSH service exposure on port 22 should be evaluated against organizational policies for cloud infrastructure. No immediate threat action is required, but continued observation is recommended given the moderate risk classification.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.64.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 245.112.118.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 245.112.118.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 1/4 domains |
| DMARC | 1/4 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 4 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | kuberneteskubernetes.defaultkubernetes.default.svckubernetes.default.svc.cluster.local |
| Valid From | 2026-08-11T05:07:20+00:00 |
| Valid Until | 2027-08-11T05:09:20+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 00F498872CE7C1A73EF35DD7038E5332C7 |
| Thumbprint | AB9019C7376BBB94BC501F1E5DCA6FAC4C3965D7 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (85%) โ 1 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-05 06:12:19 UTC |
| Last Seen | 2026-08-13 07:19:03 UTC |
| Profile Built | 2026-08-13 07:25:15 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.