# IP Intelligence Briefing: 34.181.179.200/32
Classification: Moderate Risk
Date: 2026-07-30
Prepared For: SOC Operations Team
---
## Executive Summary
IP address 34.181.179.200/32 is associated with Google Cloud infrastructure in Washington, DC. The IP demonstrates a moderate risk score of 50 and is listed on 2 of 8 DNS blacklists. No active threat indicators or malicious campaigns have been identified. The IP is configured with firewalled/no services status, indicating limited direct attack surface.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | Google LLC |
| **Network** | GOOGL-2 (34.128.0.0/10) |
| **ASN** | 396982 (GOOGLE-CLOUD-PLATFORM) |
| **Geolocation** | Washington, DC, US (38.89, -77.04) |
| **Infrastructure Type** | Cloud Compute (Google Cloud) |
| **Risk Score** | 50 (Moderate) |
| **Abuse Confidence** | Not Available |
---
## Network Classification
- Cloud Provider: Google Cloud
- Hosting: Yes
- CDN: No
- Tor Exit Node: No
- Proxy: No
- VPN: No
- Mobile/Residential: No
- Bogon: No
The IP is confirmed to be part of Google's cloud infrastructure with forward-confirmed DNS resolution to `200.179.181.34.bc.googleusercontent.com`.
---
## Threat Intelligence Indicators
Blacklist Status
- Total DNSBL Listings: 2 of 8
- Maximum Severity: High
- Campaign Associations: None identified
- Known Attacker: No
Threat Feeds
- No active threat indicators detected
- No known malicious campaigns associated
- No Tor exit node activity
---
## Temporal Analysis
Based on 13 observation records:
- Ownership Changes: 0 (stable)
- Threat Persistence: 0 days
- Threat Observation Count: 0
- Persistently Malicious: No
The IP has maintained consistent Google Cloud infrastructure classification throughout the observation period with no significant ownership or classification changes.
---
## Neighborhood Assessment
Subnet: 34.181.179.200/24
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0
No neighboring IPs in the immediate /24 subnet show elevated risk activity, indicating this IP is not part of a coordinated subnet-based abuse campaign.
---
## Relationship Graph
- Same Network: GOOGL-2 (appears twice in relationship graph)
- DNS Association: 200.179.181.34.bc.googleusercontent.com
The IP maintains standard network-level associations with the Google Cloud network block.
---
## Recommended Actions
Risk-Based Recommendation: Monitor / Block
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 34.181.179.200 -j DROP
# nftables
nft add rule inet filter input ip saddr 34.181.179.200 drop
# Cloudflare WAF
Expression: ip.src eq 34.181.179.200
Action: Block
# AWS WAF
Address: 34.181.179.200/32
Description: IPDebrief risk 50
```
Assessment Notes
- Block rule recommended due to DNSBL listings (2/8)
- No open services detected; limited exploitation vector
- Consider whitelisting if this IP is a known legitimate service
- Verify against internal allowlists before implementing block
---
## Intelligence Conclusion
This IP represents a moderate-risk cloud infrastructure address with documented DNS blacklist presence. While no active malicious activity has been observed, the blacklist association warrants defensive consideration. The absence of open services and the stable ownership profile suggest this may be a dormant or legitimately used cloud resource. SOC analysts should correlate this IP against internal threat intelligence and established allowlists before implementing blocking measures.
Confidence Level: Medium
Action Required: Review against allowlists, implement block if not whitelisted
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 200.179.181.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 200.179.181.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 04:30:31 UTC |
| Last Seen | 2026-08-12 23:08:09 UTC |
| Profile Built | 2026-08-12 23:18:10 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.