# IP INTELLIGENCE BRIEFING
Target IP: 34.14.133.201/32
Classification: Moderate Risk (Score: 50)
Reporting Timestamp: 2026-08-06
---
## EXECUTIVE SUMMARY
IP 34.14.133.201 is a Google Cloud infrastructure address with moderate risk classification. The IP is firewalled with no open services and resides within a clean subnet (34.14.133.0/24). Despite the moderate risk score, no active threat indicators were detected, and the IP shows no persistent malicious behavior.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| Organization | Google LLC |
| ASN | 396982 |
| Provider | Google Cloud |
| CIDR Block | 34.4.5.0/24 |
| RIR | ARIN |
| Network Role | Firewalled / No Services |
DNS Resolution: 201.133.14.34.bc.googleusercontent.com
Forward Resolution: Confirmed
---
## GEOLOCATION
| Attribute | Value |
|---|---|
| Country | India (IN) / United States (US)* |
| Region | Maharashtra |
| City | Mumbai |
| Accuracy Radius | 2500 km |
| Geo Consensus | True |
*Geolocation data shows some inconsistency between signals.
---
## THREAT ASSESSMENT
| Metric | Value |
|---|---|
| Risk Score | 50 |
| Abuse Confidence | N/A |
| Blacklist Count | 0 |
| DNSBL Listed | 2 / 8 |
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Threat Persistence Days | 0 |
| Persistently Malicious | No |
Threat Indicators: None detected
Campaign Associations: None detected
Known Campaigns: Empty
---
## NETWORK ENVIRONMENT
Subnet Analysis (34.14.133.0/24):
- Abuse Density: 0%
- Classification: Clean
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
Neighbor IP: 34.14.133.177 (Risk Score: 25, Authority Score: 90)
Relationship Count: 7 total (DNS associations: 4, Network associations: 3)
---
## OBSERVATION HISTORY
Total Observations: 16
Recent Activity: 2026-08-06 (multiple signals)
Key Historical Signals:
- Ownership stability: No changes observed
- Threat observation count: 0
- Threat persistence days: 0
- Service status: Consistently firewalled
---
## SECURITY ACTIONS
Recommended Actions: Block (Risk Score: 50)
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 34.14.133.201 -j DROP
# nftables
nft add rule inet filter input ip saddr 34.14.133.201 drop
# Nginx
deny 34.14.133.201;
# pfSense
34.14.133.201/32
# Cloudflare WAF
{"description":"Block 34.14.133.201 โ IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 34.14.133.201"}}
# AWS WAF
{"Addresses":["34.14.133.201/32"],"Description":"IPDebrief risk 50"}
```
---
## ANALYST NOTES
1. Infrastructure Context: Google Cloud infrastructure address with moderate risk classification. The moderate risk score warrants monitoring but does not indicate active malicious activity.
2. Service Status: IP is firewalled with no open ports detected. No TLS certificates, HTTP services, or server banners observed.
3. Network Reputation: Subnet classification is clean with zero threat siblings. Neighbor IP (34.14.133.177) shows low risk (score: 25).
4. Recommendation: Monitor for any behavioral changes. The moderate risk score combined with the Google Cloud context suggests this may be a legitimate but potentially misconfigured or high-traffic infrastructure IP. Consider blocking if the IP appears in attack traffic patterns.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.4.5.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 201.133.14.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 201.133.14.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (85%) โ 1 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-04 17:59:43 UTC |
| Last Seen | 2026-08-13 06:44:31 UTC |
| Profile Built | 2026-08-06 07:02:47 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.