# IP Intelligence Briefing: 34.148.88.195/32
Date: Analysis performed August 2026
Classification: Low Risk | Cloud Infrastructure
Risk Score: 25/100
## Executive Summary
IP 34.148.88.195 is a Google Cloud Compute instance with a low-risk profile. The IP belongs to Google LLC (ASN 396982) and operates within the GOOGL-2 network block (34.128.0.0/10). Current threat indicators show no active malicious activity, though minor anomalies in geolocation validation warrant monitoring.
## Infrastructure Profile
- Organization: Google LLC
- ASN: 396982
- Network: 34.128.0.0/10 (GOOGL-2)
- Infrastructure Type: CloudCompute (Google Cloud Platform)
- DNS Resolution: 195.88.148.34.bc.googleusercontent.com
- Email Authentication: SPF and DMARC records present
- Open Services: SSH (TCP/22) - OpenSSH 10.0
## Geographic Assessment
- Reported Location: Moncks Corner, South Carolina, US (33.21°N, -80.17°W)
- Validation Status: β οΈ Geographic inconsistency detected
- Issue: RTT measurement (42ms) indicates distance of ~6958km, which contradicts the reported South Carolina location (minimum possible RTT for 6958km should be 139.2ms)
- Geographic Confidence: Low (0.28 confidence score)
- Recommendation: Correlate with known endpoint locations; geolocation data may be inaccurate
## Threat Intelligence
- Reputation: Low Risk
- Blacklist Status: Listed on 1 of 8 DNSBL checks
- Known Malicious Indicators: None detected
- Tor/Proxy/VPN: Not classified
- Campaign Correlation: No known campaign associations
- Threat Persistence: 0 days (no persistent malicious activity)
## Neighborhood Analysis
- Subnet: 34.148.88.195/24
- Abuse Density: 0 (clean subnet)
- Threat Siblings: 0
- Active Neighbors: 0
- Classification: Clean subnet with no inherited risk
## Historical Observation
- Total Observations: 21 signals tracked
- Observation Period: Through August 2026
- Stability: No ownership changes detected
- Risk Trend: Stable low-risk profile
- Recent Signals: DNS listings, operator scores, network classification, geolocation
## Relationship Graph
- Total Relationships: 17
- Primary Associations: DNS hostname (195.88.148.34.bc.googleusercontent.com) and network (GOOGL-2)
- External Correlations: No unique relationships to external threat actors or suspicious entities
## Security Recommendations
1. Monitor SSH Access: Open SSH port (22) on cloud infrastructure requires access control validation
2. Verify Geolocation: The RTT/geographic discrepancy suggests potential misconfiguration or endpoint location mismatch
3. DNSBL Investigation: Investigate reason for single DNSBL listing; may indicate temporary abuse or false positive
4. Baseline Behavior: Establish normal traffic patterns for this GCP instance to detect anomalous activity
5. No Immediate Blocking: Current risk profile does not warrant blocking; continue monitoring
## Conclusion
IP 34.148.88.195 presents as legitimate Google Cloud infrastructure with minimal threat indicators. The primary concern is the geographic validation anomaly, which should be correlated with operational context. No immediate defensive action required beyond standard cloud infrastructure monitoring.
---
*Report generated by IPDebrief Intelligence System*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 195.88.148.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 195.88.148.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.0 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-21 19:03:26 UTC |
| Last Seen | 2026-08-12 16:16:18 UTC |
| Profile Built | 2026-08-12 16:28:05 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.