# IP Intelligence Briefing: 34.181.233.84/32
Classification: Cloud Infrastructure IP β Moderate Risk Score (50)
Date: 2026-08-13
Analyst: IPDebrief Intelligence Unit
---
## Executive Summary
IP address 34.181.233.84/32 is a Google Cloud Compute infrastructure endpoint located in Washington, DC (US). The IP maintains a moderate risk score of 50 with no active threat indicators currently observed. The address is associated with Google LLC (ASN 396982) and resolves to the googleusercontent.com domain. Historical data shows 14 observations with DNSSEC validation and SPF/DMARC authentication configured. The /24 subnet demonstrates zero abuse density and no identified threat siblings.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate) |
| **Organization** | Google LLC |
| **ASN** | 396982 (GOOGLE-CLOUD-PLATFORM) |
| **CIDR Block** | 34.128.0.0/10 |
| **Geolocation** | Washington, DC, US |
| **Infrastructure Type** | Cloud Compute |
| **Network Classification** | Provider / Hosting |
---
## Network Observations
DNS Resolution
- PTR Hostname: 84.233.181.34.bc.googleusercontent.com
- Forward Resolution: Confirmed (googleusercontent.com)
- DNSSEC Valid: Yes
- CNAME Records: Active (bc.googleusercontent.com)
Authentication Records
- SPF: Configured (include: _spf.google.com)
- DMARC: Configured (policy: none)
- TXT Record Count: 1
Service Status
- Open Ports: None detected
- HTTP Banner: No services exposed
- Connection Type: Firewalled / No Services
---
## Threat Analysis
Current Indicators
- Abuse Confidence Score: Not available
- Blacklist Count: 2 of 8 total lists (from history)
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Data
- BGP Prefix: 34.181.128.0/17
- Route Stability: Unstable (false)
- DNSBL Listings: 2 of 8 lists
- RPKI State: Not determined
---
## Neighborhood Assessment
| Metric | Value |
|---|---|
| **Subnet** | 34.181.233.84/24 |
| **Abuse Density** | 0 (Clean) |
| **Total Siblings** | 1 |
| **Active Siblings** | 0 |
| **Threat Siblings** | 0 |
| **Risk Distribution** | High: 0, Medium: 0, Low: 0 |
Assessment: The /24 subnet demonstrates zero abuse density with no neighboring IPs flagged for malicious activity.
---
## Historical Activity
Observation Count: 14 total signals
Key historical signals include:
- ASN confirmation: GOOGLE-CLOUD-PLATFORM (US)
- DNS records: CAA records present, DNSSEC validation active
- Blacklist activity: High-severity listings detected in historical data (max severity: high)
- SPF/DMARC: Both records confirmed in observation history
---
## Related Entities
Network Relationships
- Same Network: GOOGL-2 (multiple associations)
- DNS Association: 84.233.181.34.bc.googleusercontent.com
---
## Recommended Actions
Risk Score: 50 (Moderate)
Suggested Countermeasures:
| System | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 34.181.233.84 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 34.181.233.84 drop` |
| **nginx** | `deny 34.181.233.84;` |
| **pfSense** | `34.181.233.84/32` |
| **Cloudflare WAF** | `ip.src eq 34.181.233.84` β Block |
| **AWS WAF** | `Addresses: ["34.181.233.84/32"]` β Block |
Note: Recommendations are probabilistic and should be combined with additional threat intelligence signals before implementation.
---
## Analyst Notes
The moderate risk score (50) combined with the presence on multiple DNSBL lists warrants monitoring, despite the IP being Google Cloud infrastructure. The lack of open ports and clean neighborhood classification suggests the risk may be reputation-based rather than actively malicious. SOC teams should correlate with internal logs to determine if traffic from this source correlates with any observed incidents.
---
*End of Intelligence Briefing*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 84.233.181.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 84.233.181.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 8% | 2 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-12 18:31:10 UTC |
| Last Seen | 2026-08-30 21:37:15 UTC |
| Profile Built | 2026-08-29 03:53:23 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.