## IP Intelligence Briefing: 34.17.70.72/32
Classification: Google Cloud Infrastructure | Risk Level: Moderate (Score: 50) | Status: No Active Threat Indicators
Ownership & Infrastructure
- Organization: Google LLC (ASN 396982)
- Network: GOOGL-2, CIDR 34.4.5.0/24
- Infrastructure: Google Cloud provider, firewalled endpoint with no active services
- Geolocation: Turin, Italy (Piedmont region); latency validation confirms plausible location (824 km, 110.6ms avg RTT)
Network Behavior & Services
- DNS Resolution: 72.70.17.34.bc.googleusercontent.com (googleusercontent.com)
- Open Ports: None detected
- HTTP/TLS: No active web services, no certificates, no TLS termination
- Blacklist Status: 0 direct blacklists, 2 DNSBL listings across 8 total lists (likely false positives for cloud infrastructure)
Threat Assessment
- Malicious Indicators: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: 0 cert matches, 0 correlated IPs
- Historical Persistence: No persistent malicious activity observed (0 threat observation count)
Neighborhood Analysis
- Subnet: 34.17.70.72/24
- Abuse Density: 0 (clean)
- Active Siblings: 0
- Threat Siblings: 0
- Classification: Clean subnet with no malicious neighbors
Temporal Signals
- Observation Count: 17 historical signals
- Ownership Changes: 0
- Threat Persistence Days: 0
- Route Stability: Unstable (route changes within 30-day window)
Security Recommendations
Action: Monitor but no immediate blocking required. This is legitimate Google Cloud infrastructure with no exploitable services. The moderate risk score (50) reflects standard cloud provider baseline rather than malicious activity.
Firewall Rule: No action needed. If traffic patterns require scrutiny, log connections to 34.17.70.72/32 and monitor for anomalous outbound behavior.
Intelligence Note: The IP exhibits normal cloud infrastructure characteristicsโfirewalled, no open ports, legitimate DNS resolution. Risk score elevation appears to be a provider baseline flag rather than threat-based. No evidence of exploitation or command-and-control activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.4.5.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 72.70.17.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 72.70.17.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-05 00:08:23 UTC |
| Last Seen | 2026-08-13 07:03:07 UTC |
| Profile Built | 2026-08-13 07:18:25 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.