# IP Threat Intelligence Briefing
Target IP: 34.162.120.223/32
Classification: Google Cloud Infrastructure
Risk Assessment: Moderate Risk (Score: 50/100)
Date: July 30, 2026
---
## Ownership and Infrastructure
The IP address 34.162.120.223 is owned by Google LLC (ASN 396982) within the GOOGL-2 network (34.128.0.0/10). The IP is part of Google Cloud infrastructure with geolocation data indicating Columbus, Ohio, US. The reverse DNS resolves to 223.120.162.34.bc.googleusercontent.com, confirming association with Google Cloud CDN services.
## Risk Profile
Overall Risk Score: 50 (Moderate)
Risk Breakdown:
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
The IP exhibits moderate risk characteristics primarily due to DNSBL listings rather than active threat indicators. No known malicious campaigns, attacker attribution, or spam source indicators were identified.
## Threat Indicators
Abuse Confidence Score: Not applicable
Blacklist Status: Listed on 2 of 8 DNSBLs with high severity ratings
Threat Feed Associations: None
Tor Exit Node: No
Known Attacker: No
Spam Source: No
Campaign Analysis:
- Campaign Likelihood: Not determined
- Correlated IPs: 0
- Certificate Matches: 0
## Network and Service Analysis
Infrastructure Type: Google Cloud Platform
Connection Type: Firewalled / No Services
Open Ports: None detected
TLS Certificate: Not available
HTTP Services: Not available
The IP is configured with no open services, consistent with cloud infrastructure used for backend operations or content delivery.
## Geolocation Data
- Country: US
- Region: Ohio
- City: Columbus
- Coordinates: 39.83° N, -98.58° W
- Accuracy Radius: 2,500 km
- Geo Sources: 1
- Consensus: True
## Neighborhood Assessment
Subnet: 34.162.120.0/24
Abuse Density: 0 (Clean)
Classification: Clean
Total Siblings: 2
Active Siblings: 1
Threat Siblings: 0
Neighbor Analysis:
- 34.162.120.162: Risk Score 25, Authority Score 90
The /24 subnet exhibits minimal abuse activity with a clean classification.
## Observation History
Sixteen observations were recorded for this IP, with the most recent activity on July 30, 2026. Key historical signals include:
- DNS Listings: 8 total blacklist listings with 2 active high-severity entries
- Geolocation: US-based with moderate confidence (0.35)
- Ownership: Stable with no ownership changes recorded
- Network Role: Provider classification (Google Cloud)
## Recommended Security Actions
Based on the IP's risk profile, the following firewall rules are recommended:
iptables:
```bash
iptables -A INPUT -s 34.162.120.223 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 34.162.120.223 drop
```
nginx:
```nginx
deny 34.162.120.223;
```
pfSense:
```
34.162.120.223/32
```
Cloudflare WAF:
```json
{"description":"Block 34.162.120.223 β IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 34.162.120.223"}}
```
AWS WAF:
```json
{"Addresses":["34.162.120.223/32"],"Description":"IPDebrief risk 50"}
```
## Intelligence Summary
IP 34.162.120.223 is Google Cloud infrastructure with a moderate risk score of 50. The primary concern stems from DNSBL listings (2 of 8 lists, high severity), though no active threat indicators, campaigns, or known attacker attribution were identified. The IP is firewalled with no open services, consistent with legitimate cloud infrastructure usage.
Recommended Action: Apply recommended blocking rules if the IP is observed initiating connections to your infrastructure. The moderate risk score warrants investigation before permanent blocking, given the IP's legitimate cloud infrastructure ownership. Consider allowing traffic if it originates from expected Google Cloud services, or blocking if unexpected connections are observed.
---
*This briefing was generated using IPDebrief intelligence tools. All data is based on observed signals and should be validated against internal threat detection systems before taking operational action.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 223.120.162.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 223.120.162.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 04:30:31 UTC |
| Last Seen | 2026-08-12 23:07:39 UTC |
| Profile Built | 2026-08-12 23:18:11 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.