## IP Intelligence Briefing: 34.118.124.170/32
Subject: Network Intelligence Assessment
Classification: Defensive Security Intelligence
Date: Current Assessment
---
EXECUTIVE SUMMARY
IP address 34.118.124.170 was assessed as Moderate Risk (Score: 50) with no active threat indicators. The address belongs to Google Cloud infrastructure (AS396982) within the GOOGL-2 network block. While the immediate neighborhood shows no abuse density, the IP appears on 2 out of 8 queried DNSBL lists. No open services were detected; the address is firewalled with no exposed ports.
---
NETWORK OWNERSHIP & CLASSIFICATION
| Attribute | Value |
|---|---|
| **Organization** | Google LLC |
| **ASN** | 396982 |
| **Network Name** | GOOGL-2 |
| **CIDR Block** | 34.64.0.0/10 |
| **Infrastructure Type** | Cloud (Google Cloud) |
| **Geolocation** | Poland (PL), Warsaw, Mazovia |
| **Network Role** | Firewalled / No Services |
The IP resolves via reverse DNS to `170.124.118.34.bc.googleusercontent.com`, confirming Google Cloud infrastructure association.
---
THREAT INDICATORS
- Abuse Confidence Score: Not reported
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Count: 0 (threat indicators list)
- DNSBL Listed: 2 of 8 total lists
- Known Campaigns: None detected
Threat Persistence: No observed threat persistence (0 days). The IP is not classified as persistently malicious.
---
NEIGHBORHOOD ASSESSMENT
Subnet: 34.118.124.170/24
- Abuse Density: 0%
- Classification: Clean
- Threat Siblings: 0
- Active Siblings: 0
- Total Siblings: 1
The surrounding /24 subnet demonstrates no abuse activity, suggesting the moderate risk score is isolated to this specific address.
---
OBSERVATION HISTORY
Total Observations: 19 signals collected
Recent Activity (2026-08-06):
- Geographic observations indicate Warsaw, Poland with ~976km distance from probe location
- Average RTT: 117.4ms
- Traceroute: 11 hops via Comcast transit network
- No ownership changes detected
- No new threat signals emerged
Temporal Analysis: Stable ownership with zero ownership changes. No escalation in threat profile observed.
---
RECOMMENDED ACTIONS
Based on the moderate risk assessment and DNSBL listings, the following defensive measures are recommended:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 34.118.124.170 -j DROP
# nftables
nft add rule inet filter input ip saddr 34.118.124.170 drop
# Cloudflare WAF
{"description":"Block 34.118.124.170 โ IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 34.118.124.170"}}
# AWS WAF
{"Addresses":["34.118.124.170/32"],"Description":"IPDebrief risk 50"}
```
Additional Considerations:
- The IP shows no open services; blocking will impact only inbound connections
- Google Cloud infrastructure with moderate risk may indicate legitimate cloud service with some reputation concerns
- Monitor for changes in DNSBL listings over the next 30 days
---
INTELLIGENCE CONTEXT
This assessment combines real-time profile data, historical signal observation, relationship mapping, and neighborhood analysis. The IP demonstrates characteristics of a cloud-hosted service with moderate reputation challenges but no active threat activity. SOC teams should weigh the DNSBL listings against the clean neighborhood and lack of open services before implementing blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.64.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 170.124.118.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 170.124.118.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (85%) โ 1 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-04 17:59:43 UTC |
| Last Seen | 2026-08-13 06:44:10 UTC |
| Profile Built | 2026-08-06 07:02:47 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.