IPDebrief

34.162.120.223

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Threat Intelligence Briefing

Target IP: 34.162.120.223/32

Classification: Google Cloud Infrastructure

Risk Assessment: Moderate Risk (Score: 50/100)

Date: July 30, 2026

---

## Ownership and Infrastructure

The IP address 34.162.120.223 is owned by Google LLC (ASN 396982) within the GOOGL-2 network (34.128.0.0/10). The IP is part of Google Cloud infrastructure with geolocation data indicating Columbus, Ohio, US. The reverse DNS resolves to 223.120.162.34.bc.googleusercontent.com, confirming association with Google Cloud CDN services.

## Risk Profile

Overall Risk Score: 50 (Moderate)

Risk Breakdown:

The IP exhibits moderate risk characteristics primarily due to DNSBL listings rather than active threat indicators. No known malicious campaigns, attacker attribution, or spam source indicators were identified.

## Threat Indicators

Abuse Confidence Score: Not applicable

Blacklist Status: Listed on 2 of 8 DNSBLs with high severity ratings

Threat Feed Associations: None

Tor Exit Node: No

Known Attacker: No

Spam Source: No

Campaign Analysis:

## Network and Service Analysis

Infrastructure Type: Google Cloud Platform

Connection Type: Firewalled / No Services

Open Ports: None detected

TLS Certificate: Not available

HTTP Services: Not available

The IP is configured with no open services, consistent with cloud infrastructure used for backend operations or content delivery.

## Geolocation Data

## Neighborhood Assessment

Subnet: 34.162.120.0/24

Abuse Density: 0 (Clean)

Classification: Clean

Total Siblings: 2

Active Siblings: 1

Threat Siblings: 0

Neighbor Analysis:

The /24 subnet exhibits minimal abuse activity with a clean classification.

## Observation History

Sixteen observations were recorded for this IP, with the most recent activity on July 30, 2026. Key historical signals include:

## Recommended Security Actions

Based on the IP's risk profile, the following firewall rules are recommended:

iptables:

```bash

iptables -A INPUT -s 34.162.120.223 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 34.162.120.223 drop

```

nginx:

```nginx

deny 34.162.120.223;

```

pfSense:

```

34.162.120.223/32

```

Cloudflare WAF:

```json

{"description":"Block 34.162.120.223 β€” IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 34.162.120.223"}}

```

AWS WAF:

```json

{"Addresses":["34.162.120.223/32"],"Description":"IPDebrief risk 50"}

```

## Intelligence Summary

IP 34.162.120.223 is Google Cloud infrastructure with a moderate risk score of 50. The primary concern stems from DNSBL listings (2 of 8 lists, high severity), though no active threat indicators, campaigns, or known attacker attribution were identified. The IP is firewalled with no open services, consistent with legitimate cloud infrastructure usage.

Recommended Action: Apply recommended blocking rules if the IP is observed initiating connections to your infrastructure. The moderate risk score warrants investigation before permanent blocking, given the IP's legitimate cloud infrastructure ownership. Consider allowing traffic if it originates from expected Google Cloud services, or blocking if unexpected connections are observed.

---

*This briefing was generated using IPDebrief intelligence tools. All data is based on observed signals and should be validated against internal threat detection systems before taking operational action.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionOH
CityColumbus
TimezoneAmerica/New_York
Latitude39.96
Longitude-83.00

🏒 Ownership & Registration

OrganizationGoogle LLC
ASNAS396982
Network NameGOOGL-2
CIDR Block34.128.0.0/10
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR223.120.162.34.bc.googleusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames223.120.162.34.bc.googleusercontent.com

πŸ” DNS Hygiene

Hygiene Score100% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
15%
12
geolocation
27%
23
Overall21%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-29 04:30:31 UTC
Last Seen2026-08-12 23:07:39 UTC
Profile Built2026-08-12 23:18:11 UTC
Data FreshnessLive
Signal Types20
Total Observations20
πŸ” 20 signal types Β· 20 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.