# IP INTELLIGENCE BRIEFING
Target: 34.185.180.152/32
Classification: Cloud Infrastructure (Google Cloud)
Date: Current
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 34.185.180.152 is identified as legitimate Google Cloud infrastructure located in Frankfurt, Germany (DE). The IP presents a low-risk profile (Risk Score: 25) with no active threat indicators. No firewall blocking is recommended based on current intelligence.
---
## Ownership and Infrastructure
Organization: Google LLC
ASN: 396982 (GOOGL-2)
CIDR Block: 34.128.0.0/10
Infrastructure Type: CloudCompute / Hosting
Provider: Google Cloud
The IP resolves to Google's public infrastructure with PTR hostname `152.180.185.34.bc.googleusercontent.com`. DNS configuration includes SPF and DMARC records, indicating proper email authentication setup.
---
## Geolocation
Country: Germany (DE)
Region: HE (Hesse)
City: Frankfurt
Coordinates: 50.11°N, 8.68°E
Timezone: Europe/Berlin
---
## Threat Assessment
Risk Score: 25/100 (Low Risk)
Abuse Confidence: Not applicable
Blacklist Status: 0/0 (Not listed on major threat feeds)
Threat Indicators:
- Not known attacker
- Not spam source
- Not Tor exit node
- Not proxy service
- Not VPN endpoint
- Not mobile/residential
DNSBL Status: Listed on 1 of 8 threat feeds (dnsblListedCount: 1, dnsblTotalLists: 8)
---
## Network Role and Services
Classification: Cloud Compute
Connection Type: Firewall / No Services
Open Ports: None detected
TLS Certificate: None
HTTP Service: None
The IP appears to be a cloud endpoint with services blocked or non-responsive to scanning.
---
## Neighborhood Analysis
Subnet: 34.185.180.152/24
Abuse Density: 0%
Classification: Clean
Threat Siblings: 0
Active Siblings: 1
The /24 subnet exhibits no abuse activity, supporting the conclusion that this is legitimate infrastructure.
---
## Historical Observations
Total Signals: 23 observations recorded
Threat Persistence: 0 days
Ownership Changes: 0
Recent observations (June 2026) show consistent clean classification and cloud infrastructure attributes. No degradation in reputation or emergence of threat signals detected.
---
## Entity Relationships
DNS Associations: 25 relationships to googleusercontent.com hostnames
Network Associations: Multiple same-network links to GOOGL-2
Correlated IPs: None identified
Relationships indicate standard Google Cloud infrastructure patterns with DNS reverse resolution to bc.googleusercontent.com.
---
## Recommended Actions
Firewall Rules: Not recommended (Risk Score: 25)
Blocking Status: Allow (with monitoring)
Threat Feed Integration: Monitor single DNSBL listing for changes
No immediate blocking required. Standard monitoring recommended for cloud infrastructure endpoints.
---
## Conclusion
IP 34.185.180.152 is classified as Google Cloud infrastructure with a low-risk profile. The single DNSBL listing is consistent with cloud provider operational patterns and does not indicate malicious activity. No firewall rules or blocking actions are recommended. SOC analysts may treat this IP as benign unless other contextual indicators suggest otherwise.
Status: โ CLEAR - No action required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 152.180.185.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 152.180.185.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-27 07:17:38 UTC |
| Last Seen | 2026-06-29 04:01:30 UTC |
| Profile Built | 2026-06-29 04:04:10 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.