IPDebrief

34.138.217.59

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP INTELLIGENCE BRIEFING: 34.138.217.59/32

Classification: Moderate Risk (Score: 60/100)

Timestamp: 2026-08-13

---

OWNERSHIP & GEOLOCATION

The IP address is owned by Google LLC (ASN 396982), operating within the GOOGL-2 network block (34.128.0.0/10). Geolocation data indicates deployment in North Charleston, South Carolina, US. The IP is classified as a Google Cloud infrastructure asset with no open services exposed. DNS resolution points to `59.217.138.34.bc.googleusercontent.com`.

THREAT INDICATORS

The address is listed on 2 DNSBL feeds out of 8 total checks. Control plane analysis shows route stability concerns with the BGP prefix 34.138.208.0/20.

OBSERVATION HISTORY (22 Total Signals)

Recent activity on 2026-08-13 demonstrates active directory enumeration attempts by external actors:

These signals indicate reconnaissance activity targeting potential sensitive configuration files and API endpoints.

NETWORK CONTEXT

Neighboring IP analysis of the /24 subnet (34.138.217.0/24) shows zero discovered neighbors and zero abuse density, suggesting this is an isolated infrastructure node within the Google Cloud environment.

RECOMMENDED ACTIONS

1. Immediate: Increase logging verbosity for traffic from 34.138.217.59

2. Firewall Rule: Block traffic at perimeter:

- `iptables -A INPUT -s 34.138.217.59 -j DROP`

- `nft add rule inet filter input ip saddr 34.138.217.59 drop`

- Cloudflare/AWS WAF blocks also recommended

3. Monitoring: Review for any inbound connections attempting to access `/google-credentials.json`, `/privatekey.key`, `/Dockerfile`, or `/graphql` paths from this IP

---

ASSESSMENT: The IP presents moderate risk with evidence of automated directory enumeration activity. While the IP is associated with Google Cloud infrastructure, the enumeration attempts suggest either a compromised asset or a third-party scanning operation. Recommend implementing the recommended firewall rules and increasing monitoring until activity subsides.

Analyst: IPDebrief Intelligence

Source: IPDebrief Platform

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🚫
Auto-Banned IP β€” Auto-banned by enumeration detection on 2026-08-13.
Reason: Auto-ban: 5 security violations in 5min (last: enumeration/directory-enumeration)
⚠️ Admin review: pending

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionSouth Carolina
CityNorth Charleston
Timezoneβ€”
Latitude32.86
Longitude-79.97
πŸ›‘οΈ Platform Security History
HoneypotTrap endpoint probes1
EnumerationPath/resource enumeration4
Total events: 5
Observed on 2026-08-13

🏒 Ownership & Registration

OrganizationGoogle LLC
ASNAS396982
Network NameGOOGL-2
CIDR Block34.128.0.0/10
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR59.217.138.34.bc.googleusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames59.217.138.34.bc.googleusercontent.com

πŸ” DNS Hygiene

Hygiene Score100% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpβ€”
Closed Ports22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
CN=tarsier.cloudshell.svc
Issued by CN=tarsier.cloudshell.svc
Self-signed: Yes
SANsNone
Valid From2026-08-27T13:58:44+00:00
Valid Until2026-11-25T13:58:44+00:00

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
35%
22
Overall18%55
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-08-10 05:12:01 UTC
Last Seen2026-08-30 22:47:37 UTC
Profile Built2026-08-30 22:54:09 UTC
Data FreshnessLive
Signal Types24
Total Observations31
πŸ” 24 signal types Β· 31 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.