## IP Intelligence Briefing: 34.156.187.171/32
Classification: Cloud Infrastructure Asset | Risk Level: Low Risk
Date Generated: Current
Analyst: IPDebrief Intelligence Team
---
Executive Summary
IP 34.156.187.171 is a low-risk Google Cloud Platform (GCP) infrastructure address. The IP operates within the 34.156.128.0/17 BGP prefix and resolves to a Google-owned domain (googleusercontent.com). Current risk assessment indicates minimal threat activity, though the IP maintains a DNSBL listing on one of eight queried lists.
Technical Profile
- Organization: Google LLC (ASN: 396982)
- Infrastructure: Cloud Compute (Google Cloud Platform)
- Risk Score: 25/100 (Low Risk)
- Reputation: Low Risk
- Open Ports: TCP/443 (HTTPS)
- DNS PTR: 171.187.156.34.bc.googleusercontent.com
- TLS Certificate: Self-signed certificate issued for Kubernetes cluster (CN=kubernetes, CN=kubernetes.default)
Geolocation Analysis
The IP exhibits geolocation inconsistencies in probe data:
- Primary consensus: United States (ARIN registry)
- Recent observations (2026-06-28): Brussels, Belgium (St. Ghislain)
- Accuracy radius: 2,500 km
These variations are consistent with GCP's multi-region deployment architecture and should not be treated as malicious spoofing.
Threat Indicators
- Abuse Confidence Score: Not applicable (cloud infrastructure)
- Blacklist Count: 1 of 8 DNSBL lists
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Historical Risk Trends
Analysis of 30 signal observations reveals:
- Recent Activity: June 22-28, 2026
- Risk Trend: Stable low-risk profile
- Operator Score: 0 (minimal threat signals)
- Threat Persistence: 0 days
- Ownership Changes: 0
The IP has maintained consistent cloud infrastructure characteristics without significant threat escalation.
Network Relationships
- DNS Associations: googleusercontent.com hostnames
- Network Affiliations: GOOGL-2 network family
- Relationship Count: 297 total entities
Neighborhood Analysis
- Subnet: 34.156.187.0/24
- Abuse Density: 0 (clean)
- Classification: Mostly clean
- Risk Distribution: No high-risk siblings detected
- Siblings: 1 active, 1 threat-flagged
Recommended Actions
SOC Analyst Guidance:
1. No immediate blocking required - IP operates as legitimate cloud infrastructure
2. Monitor DNSBL listing - Investigate why 1 of 8 lists flags this IP
3. Allow HTTPS traffic - Standard cloud service port 443
4. No firewall rules - Standard egress allowed for cloud infrastructure
5. No IP reputation filtering - Low risk profile appropriate for whitelist consideration
Conclusion
34.156.187.171 is a benign Google Cloud Platform address supporting web services. The single DNSBL listing warrants minimal investigation but does not indicate active malicious behavior. No SOC blocking or filtering actions recommended. This IP represents normal cloud infrastructure operations rather than a threat source.
---
*Report generated from IPDebrief intelligence platform. All data verified through multi-source correlation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 171.187.156.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 171.187.156.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 1/4 domains |
| DMARC | 1/4 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 4 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | kuberneteskubernetes.defaultkubernetes.default.svckubernetes.default.svc.cluster.local |
| Valid From | 2026-05-22T05:38:51+00:00 |
| Valid Until | 2027-05-22T05:40:51+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 00F893DF62DBB7B5F51298F8C1F055986C |
| Thumbprint | 8D6114832CB0F837814C442B6152ABD71A3553B9 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 03:36:03 UTC |
| Last Seen | 2026-06-28 08:25:50 UTC |
| Profile Built | 2026-06-29 02:30:37 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 35 |
Full dossier details are available via our API.