## IP Intelligence Briefing: 34.148.224.3/32
Date: August 2026
Analyst: IPDebrief Intelligence Team
Classification: Moderate Risk Assessment
---
Executive Summary
IP 34.148.224.3/32 is a Google Cloud infrastructure endpoint registered to the GOOGL-2 network (ASN 396982). The asset demonstrates moderate risk scoring (40/100) driven primarily by control plane DNSBL listings, despite legitimate cloud infrastructure indicators. No active threat campaigns or malicious indicators were observed across the investigation period.
---
Technical Profile
Ownership & Classification:
- Organization: Google LLC (GOOGL-2)
- ASN: 396982
- CIDR Block: 34.128.0.0/10
- Infrastructure Type: Google Cloud Platform
- Network Role: Single-Service Host
Geolocation:
- Country: United States (US)
- Region: South Carolina (SC)
- City: Moncks Corner
- Coordinates: 33.21, -80.17
Network Services:
- Port 22/TCP: SSH enabled (OpenSSH 9.6p1 Ubuntu-3ubuntu13.18)
- Reverse DNS: 3.224.148.34.bc.googleusercontent.com
- Forward Resolution: Confirmed
---
Threat Assessment
Risk Indicators:
- Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Data:
- DNSBL Listings: 2 of 8 total lists
- Operator Score: 0.3478 (Basic)
- Route Stability: Not stable (route changes detected in 30-day window)
- RPKI State: Not validated
---
Historical Observations
Analysis of 23 historical observations indicates consistent Google Cloud infrastructure classification. The most recent observation (2026-08-13) confirms:
- Cloud infrastructure classification (not CDN, VPN, or proxy)
- No Tor/VPN/proxy indicators
- Low-confidence threat assessments across dimensions
No evidence of persistent malicious activity was detected. The IP has demonstrated stable ownership characteristics with zero ownership changes recorded.
---
Neighborhood Analysis
Subnet: 34.148.224.0/24
- Abuse Density: 0%
- Classification: Clean
- Active Siblings: 1
- Threat Siblings: 0
The immediate /24 subnet shows no sibling abuse indicators, suggesting this is an isolated endpoint rather than part of a coordinated threat infrastructure.
---
Relationships
The IP maintains DNS associations with googleusercontent.com hostnames and is associated with the GOOGL-2 network. No external organization relationships or certificate associations were identified beyond standard Google Cloud infrastructure patterns.
---
Recommended Actions
Firewall Configuration:
- Block at perimeter: iptables/nftables DROP rule recommended
- Cloudflare WAF: Block with expression "ip.src eq 34.148.224.3"
- AWS WAF: Block address 34.148.224.3/32
Assessment: While the IP presents moderate risk scoring due to DNSBL listings, the underlying infrastructure is legitimate Google Cloud. Blocking may be warranted if the IP is associated with specific suspicious activity in organizational logs. The moderate risk score warrants correlation with other threat signals before enforcement actions.
---
Disclaimer: This briefing represents intelligence gathered from IPDebrief threat intelligence data. SOC teams should correlate with internal security logs and threat feeds before implementing blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 3.224.148.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 3.224.148.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-01 16:33:38 UTC |
| Last Seen | 2026-08-13 02:50:09 UTC |
| Profile Built | 2026-08-13 03:00:06 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.