# IP Intelligence Briefing: 34.20.215.214/32
Classification: Moderate Risk
Date: 2026-08-12
Analyst: IPDebrief Intelligence Team
## Executive Summary
IP address 34.20.215.214 belongs to Google Cloud infrastructure (ASN 396982, GOOGL-2 network) and presents a moderate risk profile. The IP is associated with cloud infrastructure in Los Angeles, California (US) and shows no active open ports or service exposure. Risk indicators include DNSBL listings on 2 of 8 threat intelligence feeds and control plane instability.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate) |
| **Organization** | Google LLC |
| **ASN** | 396982 |
| **CIDR Block** | 34.20.128.0/17 |
| **Geolocation** | Los Angeles, CA, US |
| **Provider** | Google Cloud |
| **DNS Record** | 214.215.20.34.bc.googleusercontent.com |
| **Cloud Infrastructure** | Yes |
| **Open Ports** | None detected |
| **Blacklist Count** | 2 of 8 threat feeds |
## Risk Assessment
The IP received a moderate risk score of 50, primarily driven by control plane instability (route changes observed within 30-day window) and DNSBL presence. No known attacker campaigns, spam source activity, or Tor exit node associations were identified. The IP demonstrates forward DNS confirmation and valid DNSSEC/CAA records.
Key Risk Indicators:
- DNSBL listings: 2 positive matches across 8 total feeds
- Route instability: Route changes detected in recent 30-day period
- No service exposure: No open ports or running services detected
Mitigating Factors:
- Legitimate cloud provider (Google Cloud)
- No active threat indicators
- No known malicious activity in observation history
- Infrastructure appears properly configured
## Observation History
Signal observation history contains 21 data points, with the most recent observation recorded on 2026-08-12. The IP has demonstrated consistent cloud infrastructure classification throughout the observation period. Operator score remains at basic level (0.3478). No ownership changes have been observed.
## Network Relationships
The IP maintains 14 relationship entries, primarily DNS associations to hostname 214.215.20.34.bc.googleusercontent.com and network associations to GOOGL-2. These relationships confirm legitimate cloud infrastructure deployment.
## Neighborhood Analysis
Subnet 34.20.215.0/24 shows zero active neighbors and zero abuse density. The subnet classification is "mostly_clean" with inherited risk of 2. No threat siblings were identified in the /24 block.
## Recommended Actions
The system generated firewall rules for multiple platforms. Due to the moderate risk score and cloud provider context, analysts should evaluate business requirements before implementing blocking rules. Recommended approach:
1. Monitor traffic patterns for anomalous behavior
2. Block only if correlated with confirmed malicious activity
3. Allow if traffic matches legitimate Google Cloud service patterns
Firewall Rules (for reference):
- iptables: `iptables -A INPUT -s 34.20.215.214 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 34.20.215.214 drop`
- Cloudflare WAF: Block with expression `ip.src eq 34.20.215.214`
- AWS WAF: Add address `34.20.215.214/32` to block list
## Conclusion
IP 34.20.215.214 is a Google Cloud infrastructure address with moderate risk. While no active threats were identified, the DNSBL listings and route instability warrant monitoring. Immediate blocking is not recommended without additional context or correlation with other threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.4.5.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 214.215.20.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 214.215.20.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 28% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 10:34:11 UTC |
| Last Seen | 2026-08-12 23:27:25 UTC |
| Profile Built | 2026-08-13 00:08:27 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.