IP INTELLIGENCE BRIEFING: 34.19.202.222/32
Classification: Moderate Risk | Risk Score: 40/100 | Date: Current Analysis
---
Executive Summary
IP 34.19.202.222 is associated with Google Cloud infrastructure (ASN 396982, organization: Google LLC). The IP demonstrates moderate risk characteristics with a risk score of 40, primarily driven by control plane instability and DNSBL listings. No active threat indicators or malicious campaign correlations were identified. The IP resolves to a Google Cloud endpoint with no open services detected.
---
Ownership and Infrastructure
- Organization: Google LLC
- AS Number: 396982 (GOOGL-2)
- CIDR Block: 34.4.5.0/24
- Network Role: Google Cloud provider
- Infrastructure Type: Cloud-based
- BGP Prefix: 34.19.128.0/17
- Route Stability: Unstable (route changes observed)
---
Geolocation Analysis
- Reported Location: Montreal, Quebec, Canada (CA)
- Geolocation Validation: FAILED
- RTT Violation: 26ms observed vs. minimum possible 112ms for 5,598km distance
- GeoPlausible flag: False
- Recommendation: Geographic data unreliable; treat as cloud-origin IP from US or global edge location
---
Threat Intelligence
- Abuse Confidence Score: Not applicable
- Blacklist Status: Listed on 2 of 8 DNSBL feeds
- Known Threat Indicators: None
- Tor Exit Node: No
- Known Attacker/Spam Source: No
- Campaign Correlation: None detected
- Threat Persistence: 0 days observed
---
Network Neighborhood Assessment
- Subnet: 34.19.202.222/24
- Abuse Density: 0 (clean classification)
- Threat Siblings: 0
- Active Siblings: 0
- Total Siblings: 1
- Risk Distribution: No high or medium risk neighbors detected
---
DNS and Service Analysis
- PTR Record: 222.202.19.34.bc.googleusercontent.com
- Forward Resolution: Confirmed (googleusercontent.com)
- Open Ports: None detected
- TLS Certificate: Not present
- Service Banner: None
- Email Auth: SPF and DMARC records present
---
Observations History
17 signal observations recorded. Recent activity shows consistent ownership attribution to Google LLC with no changes. Geolocation signals show inconsistency across probes, suggesting cloud-based dynamic routing or data center placement.
---
Recommended Actions
Risk Score: 40 (Moderate Risk)
Recommended Security Controls:
1. Firewall: Block traffic at perimeter
- iptables: `iptables -A INPUT -s 34.19.202.222 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 34.19.202.222 drop`
2. Web Application Firewall: Configure block rule
- Cloudflare WAF: Block IP with expression `ip.src eq 34.19.202.222`
- AWS WAF: Add IP 34.19.202.222/32 to block list
3. Monitoring: Add to SIEM for traffic pattern analysis
Note: As this IP belongs to Google Cloud infrastructure, consider business context before blocking. False positives may occur if legitimate traffic originates from this range.
---
Intelligence Conclusion
IP 34.19.202.222 presents moderate risk primarily due to control plane instability and DNSBL listings. The IP is cloud-based (Google Cloud) with no open services or active threat indicators. The subnet exhibits clean classification with no malicious neighbors. SOC teams should evaluate based on organizational policy for cloud provider IPs and consider the moderate risk score alongside business context before implementing blocking rules.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.4.5.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 222.202.19.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 222.202.19.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-01 16:33:39 UTC |
| Last Seen | 2026-08-13 02:53:00 UTC |
| Profile Built | 2026-08-13 03:05:38 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.