## IP Intelligence Briefing: 34.174.106.197/32
Classification: Low Risk / Infrastructure
Date: Current Assessment
Analyst: IPDebrief Intelligence Team
Executive Summary
The target IP 34.174.106.197 was classified as Low Risk with a risk score of 25. The address is confirmed Google Cloud infrastructure operating within the GOOGL-2 network (34.128.0.0/10). No active threat indicators or malicious activity patterns were detected during the assessment.
Ownership and Attribution
- Organization: Google LLC (ASN 396982)
- Network Registration: GOOGL-2, ARIN
- Geolocation: Dallas, TX, US (Region: TX)
- Infrastructure Type: Google Cloud Provider, Web Server
Technical Profile
DNS Resolution:
- PTR Hostname: 197.106.174.34.bc.googleusercontent.com
- Forward Resolution: 197.106.174.34.bc.googleusercontent.com (confirmed)
- Domain: googleusercontent.com
Service Exposure:
- Port 443/TCP (HTTPS) open
- TLS Certificate: CN=34.174.148.56 with Kubernetes service SANs (kubernetes, kubernetes.default, kubernetes.default.svc)
- HTTP2 protocol enabled
- HSTS: Not implemented
- CSP: Not implemented
Control Plane:
- BGP Prefix: 34.174.0.0/17
- Origin ASN: 396982 (Google LLC)
- RPKI State: Not validated
- DNSSEC: Valid
Threat Indicators
- Risk Score: 25 (Low)
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- DNSBL Listings: 1 out of 8 lists
Historical Analysis
25 signal observations recorded over the monitoring period. Historical data indicates consistent Google Cloud infrastructure classification with no persistent malicious behavior patterns. Recent DNS signals associated with Kubernetes service discovery (cluster.local, default.svc, kubernetes.default), consistent with legitimate cloud workload identification. No ownership changes or threat persistence indicators observed.
Network Neighborhood
- Subnet: 34.174.106.197/24
- Abuse Density: 0.0 (Clean)
- Threat Siblings: 0
- Classification: Clean subnet
Intelligence Assessment
The IP address 34.174.106.197 operates as legitimate Google Cloud infrastructure hosting web services. The associated TLS certificate indicates Kubernetes container orchestration workloads. No adversarial indicators, abuse patterns, or threat intelligence correlations were identified. The IP does not require blocking or mitigation at this time.
Recommended Actions
No firewall rules or mitigation actions recommended. The IP score of 25 with clean neighborhood classification indicates standard Google Cloud infrastructure operations. Continue monitoring if the IP appears in security event logs as a source or destination, but no immediate defensive action is warranted.
---
*End of Intelligence Briefing*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 197.106.174.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 197.106.174.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 1/4 domains |
| DMARC | 1/4 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 4 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | kuberneteskubernetes.defaultkubernetes.default.svckubernetes.default.svc.cluster.local |
| Valid From | 2026-07-31T04:01:00+00:00 |
| Valid Until | 2027-07-31T04:03:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 00D4E59E100FAD808E03BB7203401D76E3 |
| Thumbprint | A33CAA860A04A3FB6401004BC176534889C01073 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 32% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 04:03:07 UTC |
| Last Seen | 2026-08-12 22:12:58 UTC |
| Profile Built | 2026-08-12 22:21:27 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.