## IP INTELLIGENCE BRIEFING: 34.140.177.86/32
Classification: Moderate Risk (Risk Score: 65/100)
Report Date: 2026-08-13
Intel Level: SOC Analyst Review Required
EXECUTIVE SUMMARY
IP address 34.140.177.86 is a Google Cloud infrastructure endpoint associated with the GOOGL-2 CIDR block (34.128.0.0/10). The IP presents moderate risk due to DNSBL listings despite legitimate cloud provider infrastructure. Enhanced monitoring recommended.
OWNERSHIP & NETWORK CLASSIFICATION
- Organization: Google LLC (ASN: 396982)
- Network Name: GOOGL-2
- RIR: ARIN
- CIDR Block: 34.128.0.0/10
- Infrastructure Type: Cloud Compute (Google Cloud)
- Network Role: Single-Service Host
GEOLOCATION DATA
- Country: Belgium (BE)
- Region: Brussels Capital
- City: Brussels
- Geo Validation: Plausible (5 probes, avg RTT: 93.2ms)
- DNS Resolution: 86.177.140.34.bc.googleusercontent.com
THREAT INDICATORS
- Risk Score: 65/100 (Moderate Risk)
- DNSBL Listings: 3 of 8 total lists
- Abuse Confidence: Not explicitly scored
- Tor Exit Node: No
- Known Attacker: No
- Known Spam Source: No
- Campaign Likelihood: None
NETWORK SERVICES & FINGERPRINT
- Open Ports: TCP/22 (SSH - OpenSSH_9.6p1 Ubuntu-3ubuntu13.18)
- TLS Certificate: None detected
- HTTP Title: None detected
- Server Banner: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
OBSERVATION HISTORY
- Total Observations: 23
- Recent Classification: Google Cloud infrastructure (is_cloud: true)
- DNSBL Activity: 2026-08-13T04:24:12Z - Listed on 8 DNSBLs with high severity
- Geolocation Variance: One observation showed New York, US (potential anycast or routing variation)
- Operator Score: 0.3478 (Basic)
NETWORK NEIGHBORHOOD ANALYSIS
- Subnet: 34.140.177.86/24
- Abuse Density: 0% (clean)
- Threat Siblings: 0
- High/Medium Risk Neighbors: 0
- Overall Classification: Clean subnet environment
RELATIONSHIP GRAPH
- DNS Associations: 86.177.140.34.bc.googleusercontent.com (13 relationship entries)
- Network Associations: GOOGL-2 (6 relationship entries)
- No external organization or hostname diversity
RECOMMENDED ACTIONS
Primary Recommendation: Increase logging verbosity and review recent activity from this IP (Severity: High)
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 34.140.177.86 -j DROP
# nftables
nft add rule inet filter input ip saddr 34.140.177.86 drop
# Cloudflare WAF
ip.src eq 34.140.177.86 โ Block
# AWS WAF
Addresses: 34.140.177.86/32
```
ANALYST NOTES
The elevated risk score (65/100) stems primarily from DNSBL listings rather than confirmed malicious activity. The IP operates Google Cloud infrastructure with SSH access enabled. The subnet (34.140.177.86/24) shows no neighboring abuse activity. Consider whether blocking is appropriate based on your threat context, or implement enhanced logging for visibility into activity patterns. The DNSBL listings warrant investigation to determine if the IP is being misused or if there are false positives.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 86.177.140.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 86.177.140.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-02 23:10:25 UTC |
| Last Seen | 2026-08-13 04:19:18 UTC |
| Profile Built | 2026-08-13 04:27:43 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.