# INTELLIGENCE BRIEFING: 34.187.255.15/32
## Executive Summary
IP address 34.187.255.15 is assigned to Google LLC within the 34.128.0.0/10 CIDR block. The IP presents a moderate risk score of 50 with no direct threat indicators. The endpoint is firewalled with no active services, resolves to Google Cloud infrastructure in Oregon, and operates within a clean neighborhood subnet.
## Ownership and Infrastructure
- Organization: Google LLC (ASN 396982)
- Network Name: GOOGL-2
- CIDR Block: 34.128.0.0/10
- RIR: ARIN
- Infrastructure Type: Google Cloud provider
## Geolocation
- Country: United States (US)
- Region: Oregon
- City: The Dalles
- Geographic Accuracy: ±2,500 km radius
- Geo-Consensus: Verified across multiple sources
## Network Classification
- Primary Role: Google Cloud infrastructure
- Service Status: Firewalled / No Services
- Open Ports: None detected
- Anycast: Not detected
- Bogon: No
## DNS Analysis
- Reverse DNS: 15.255.187.34.bc.googleusercontent.com
- Forward Resolution: Confirmed
- Email Authentication: SPF and DMARC records present
- TXT Records: 0 entries
## Threat Intelligence
- Risk Score: 50 (Moderate Risk)
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- Known Campaigns: None detected
- Campaign Likelihood: None
- Threat Persistence: 0 days observed
- Persistently Malicious: False
## Control Plane Assessment
- Origin ASN: 396982
- BGP Prefix: 34.187.128.0/17
- Route Stability: False
- DNSBL Listings: 2 of 8 total lists
- RPKI State: Not evaluated
- IRR Consistency: Not evaluated
## Neighborhood Analysis (34.187.255.0/24)
- Abuse Density: 0% (Clean)
- Subnet Classification: Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- Inherited Risk: 0
## Observation History
19 historical observations recorded. Recent signals confirm consistent ownership attribution to Google LLC with no evidence of persistent malicious activity. Ownership changes: 0. Threat observation count: 0.
## Relationships
DNS associations link the IP to the hostname 15.255.187.34.bc.googleusercontent.com. Network relationships confirm membership in the GOOGL-2 network block.
## Recommended Security Actions
Firewall Rules:
- iptables: `iptables -A INPUT -s 34.187.255.15 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 34.187.255.15 drop`
- nginx: `deny 34.187.255.15;`
- pfSense: `34.187.255.15/32`
Cloud WAF Configurations:
- Cloudflare: Block IP with expression `ip.src eq 34.187.255.15`
- AWS WAF: Add IP 34.187.255.15/32 with description "IPDebrief risk 50"
Analysis Notes:
Recommendation to block is based on moderate risk score of 50. While the IP is associated with Google Cloud infrastructure and shows no direct threat indicators, the presence of DNSBL listings (2 of 8) and the firewalled nature of the endpoint warrant consideration for blocking in sensitive environments. The clean neighborhood classification and consistent ownership history suggest this is legitimate cloud infrastructure that may be firewalled for security hardening. SOC analysts should validate against local security context before implementing blocking rules.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.128.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 15.255.187.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 15.255.187.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (85%) β 1 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 11:03:57 UTC |
| Last Seen | 2026-08-13 00:39:17 UTC |
| Profile Built | 2026-08-06 00:50:27 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 27 |
Full dossier details are available via our API.