## IP Intelligence Briefing: 34.181.149.120/32
Date: 2026-08-13
Classification: Google Cloud Infrastructure - Moderate Risk
Executive Summary
IP address 34.181.149.120 is assigned to Google LLC (ASN 396982) within the GOOGL-2 network block (34.128.0.0/10). The address resolves to Google Cloud infrastructure under the hostname 120.149.181.34.bc.googleusercontent.com. Risk assessment indicates moderate concern (65/100) with no evidence of persistent malicious activity, though the IP appears on three DNS blacklists.
Ownership & Network Context
- Organization: Google LLC
- ASN: 396982
- CIDR Block: 34.128.0.0/10
- RIR: ARIN
- Infrastructure Type: Google Cloud Platform
- Contact: google-cloud-compliance@google.com
Threat Assessment
- Risk Score: 65/100 (Moderate)
- DNSBL Status: Listed on 3 of 8 checked lists
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not reported
The elevated risk score correlates with DNSBL listings, though the IP shows no historical persistent malicious behavior and belongs to a cloud provider infrastructure with standard firewalled configuration.
Geolocation & Validation
- Reported Location: Washington, District of Columbia, US
- Geolocation Consensus: Multiple sources indicate US
- Plausibility Flag: Geo data flagged as implausible
- Validation Issue: RTT measurement (27ms) is below the minimum possible latency (125.9ms) for the claimed distance of 6,295.7km, indicating geolocation data may be inaccurate
Neighborhood Analysis
- Subnet: 34.181.149.120/24
- Abuse Density: 0
- Classification: Clean
- Active Threat Siblings: 0
- Total Siblings: 1
The /24 neighborhood shows no abuse activity, suggesting the risk is isolated to this specific IP rather than representing broader network compromise.
Observation History (17 Signals)
Recent activity includes:
- Ownership confirmation (Google LLC, ARIN)
- Subnet classification as clean
- Geolocation signals (US, with validation warnings)
- No observed threat persistence or malicious behavior over time
Recommended Actions
Due to the elevated risk score (65/100) and DNSBL listings, the following actions are recommended:
1. Logging: Increase logging verbosity and review all recent activity from this IP
2. Blocking Consideration: Implement blocking if legitimate use cannot be verified
3. Verification: Confirm whether this IP should be allowed based on organizational policy
Recommended Firewall Rules
- iptables: `iptables -A INPUT -s 34.181.149.120 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 34.181.149.120 drop`
- nginx: `deny 34.181.149.120;`
- pfSense: Block 34.181.149.120/32
- Cloudflare WAF: Block IP with expression `ip.src eq 34.181.149.120`
- AWS WAF: Add to blocked addresses list with CIDR 34.181.149.120/32
Conclusion
While this IP belongs to legitimate Google Cloud infrastructure with no evidence of persistent malicious activity, the moderate risk score and DNSBL listings warrant increased monitoring. The neighborhood is clean, suggesting isolated risk. SOC teams should balance the known cloud provider attribution against the blacklisting data before applying blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 120.149.181.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 120.149.181.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-12 18:31:10 UTC |
| Last Seen | 2026-08-27 09:58:32 UTC |
| Profile Built | 2026-08-29 04:38:05 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.