IP Intelligence Briefing: 34.131.231.115
*Generated via IPDebrief Analysis*
---
**1. Core Profile**
- Ownership:
- ISP: Google LLC (AS396982)
- Network: GOOGL-2 (arin-registered)
- Geolocation: New York, NY, US (latitude: 40.7128, longitude: -74.0060)
- Risk Score: Moderate (50/100)
- Threat Indicators:
- No current known malicious activity (no indicators, blacklists, or campaigns).
- Historical Data: Observed in New Delhi, India (2026-06-16) with "has_threats": true (alienvault-otx).
- Network Role:
- Provider: Google Cloud
- Services: No open ports; TLS/HTTP scans yielded no banners or certs.
- Classification: Firewalled / No Services
---
**2. Observation History**
- Recent Activity (2026-06-16):
- DNS: Resolved to `115.231.131.34.bc.googleusercontent.com` (Google CDN).
- Threat Signals:
- Listed in 2/8 DNSBLs (high severity).
- Geolocation mismatch (New York vs. New Delhi).
- Behavior: No persistent malicious activity detected.
---
**3. Relationships**
- DNS:
- Linked to `googleusercontent.com` (valid DNSSEC, CAA records).
- Network:
- Same ASN (AS396982) and network block (GOOGL-2).
- No Known Malicious Associations:
- No correlated IPs, domains, or certificates flagged as malicious.
---
**4. Subnet Neighbors**
- Subnet: 34.131.231.0/24
- Neighbor Risk Distribution:
- Moderate Risk: 1 IP (34.131.231.204, score: 50)
- Low Risk: 1 IP (34.131.231.242, score: 25)
- Abuse Density: 0% (no suspicious activity in subnet).
---
**5. Recommendations**
- Monitor:
- Track historical geolocation anomalies (New Delhi) for potential IP spoofing or misconfigured cloud instances.
- Network:
- Confirm subnet segmentation policies to isolate high-risk neighbors.
- DNS:
- Validate DNSSEC and CAA records for `googleusercontent.com` to ensure no spoofing.
- Threat Intelligence:
- Cross-reference with DNSBLs for updated threat status.
Conclusion: The IP is part of Googleβs infrastructure with no active threats, but historical data suggests potential misconfigurations or compromised cloud instances. SOC teams should monitor for anomalies and ensure strict network segmentation.
*Data sourced from IPDebrief as of 2026-06-16.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 115.231.131.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 115.231.131.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | kuberneteskubernetes.defaultkubernetes.default.svckubernetes.default.svc.cluster.local |
| Valid From | 2026-06-21T09:23:04+00:00 |
| Valid Until | 2031-06-20T09:25:04+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 1825 days |
| Serial Number | 00B83A3C3EB4CDF508FF31880A0AF43754 |
| Thumbprint | B2485B39F1F8483F6AF86F3D26CA0FD2318B0495 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 24% | 9 | 12 |
| Data Coherence | Mostly Consistent (85%) β 1 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-15 11:54:51 UTC |
| Last Seen | 2026-06-21 23:16:33 UTC |
| Profile Built | 2026-06-21 23:29:26 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.