INTELLIGENCE BRIEFING: 34.180.47.216
Classification: Cloud Infrastructure IP
Date: 2026-08-06
Analyst: IPDebrief SOC Team
---
EXECUTIVE SUMMARY
IP 34.180.47.216 is a Google Cloud Platform (GCP) compute instance with a Low Risk reputation score of 25. No malicious threat indicators, campaigns, or blacklist associations were identified. The IP exhibits normal cloud infrastructure behavior with standard SSH services exposed.
---
OWNERSHIP & INFRASTRUCTURE
- Organization: Google LLC
- ASN: 396982 (GOOGL-2)
- CIDR Block: 34.128.0.0/10 (Google Cloud)
- Network Type: CloudCompute / Single-Service Host
- Infrastructure: Google Cloud Platform
---
GEOLOCATION DATA
- Reported Location: Mumbai, India (IN)
- Coordinates: 19.08°N, 72.88°E
- Confidence: Limited (geoConsensus: false, geoPlausible: false)
- Note: Geolocation data shows some inconsistency with alternative signals indicating New York, US. This is common for cloud providers using routing-based geolocation services.
---
DNS & HOSTING
- PTR Record: 216.47.180.34.bc.googleusercontent.com
- Forward DNS: Confirmed (googleusercontent.com)
- Email Authentication: SPF and DMARC configured
- Reverse DNS Resolution: Forward confirmed
---
NETWORK SERVICES
- Open Ports: TCP/22 (SSH)
- SSH Banner: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
- HTTPS/TLS: No certificate detected
- HTTP: No web service detected
- Classification: Single-Service Host
---
THREAT INDICATORS
- Risk Score: 25 (Low)
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None
- DNSBL Listings: 1 of 8 total lists
- Abuse Confidence Score: Not applicable
---
OBSERVATION HISTORY
- Total Observations: 18
- Recent Activity: Last observed 2026-08-06
- Threat Persistence: 0 days
- Ownership Changes: 0
- Status: No persistently malicious behavior detected
---
NETWORK RELATIONSHIPS
- Total Relationships: 7
- Primary Associations: GOOGL-2 network (multiple "Same Network" links)
- DNS Associations: bc.googleusercontent.com hostnames
- No suspicious external correlations identified
---
SUBNET ANALYSIS (34.180.47.0/24)
- Abuse Density: 0
- Threat Siblings: 0
- High/Medium Risk Neighbors: 0
- Observation: Subnet appears clean with no sibling abuse patterns
---
RECOMMENDATIONS FOR SOC ANALYSTS
1. Monitor SSH Traffic: Standard GCP compute instance with SSH exposed. Verify if this is expected for your environment.
2. GeoValidation: Consider validating the Mumbai location against your deployment expectations if this IP should be US-based.
3. No Immediate Action Required: Risk profile indicates legitimate cloud infrastructure. No firewall blocking recommended.
4. Contextual Analysis: If traffic from this IP is unexpected, investigate application-layer behavior rather than IP reputation alone.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 216.47.180.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 216.47.180.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 1 | 1 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 1 |
| geolocation | 24% | 2 | 2 |
| Overall | 22% | 9 | 10 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-01 22:41:52 UTC |
| Last Seen | 2026-08-13 03:13:14 UTC |
| Profile Built | 2026-08-13 03:25:43 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.