IPDebrief

34.21.87.139

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: IP 34.21.87.139

Classification: Moderate Risk Infrastructure IP

Generated: 2026-06-19

Analyst: IPDebrief Intelligence Team

---

## EXECUTIVE SUMMARY

IP address 34.21.87.139 is a Google Cloud infrastructure endpoint associated with googleusercontent.com. The IP presents a moderate risk profile (risk score: 50) with no direct threat indicators, though it appears on 2 of 8 DNSBLs with one listing marked as high severity. The address is part of Google's cloud compute infrastructure in Washington, DC. No open ports or active services were detected during probing.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
OrganizationGoogle LLC
ASN396982
CIDR Block34.21.0.0/17
GeolocationWashington, DC, US
Infrastructure TypeCloudCompute (Google Cloud)
PTR Hostname139.87.21.34.bc.googleusercontent.com

Key Findings:

---

## THREAT ASSESSMENT

Overall Risk Score: 50 (Moderate Risk)

IndicatorStatus
Is Known AttackerNo
Is Tor Exit NodeNo
Is Spam SourceNo
Blacklist Count0
DNSBL Listed2 of 8
Threat PersistenceNot Persistently Malicious

DNSBL Analysis:

---

## OBSERVATION HISTORY

Total Observations: 25 signals over monitoring period

Notable Events:

Temporal Analysis:

---

## NETWORK RELATIONSHIPS

Total Relationships: 42

Primary Associations:

Campaign Correlation:

---

## NEIGHBORHOOD ANALYSIS

Subnet: 34.21.87.139/24

MetricValue
Abuse Density0
Classificationmostly_clean
Inherited Risk2
Total Siblings1
Active Siblings1
Threat Siblings1

Assessment: Subnet shows low abuse density with minimal threat indicators. The IP appears isolated in terms of malicious activity within its /24 block.

---

## GEOVALIDATION

MetricValue
Reported Distance6,295.7 km
Minimum Possible RTT125.9 ms
Observed RTT23 ms
Minimum RTT Observed23 ms
Average RTT26 ms
Probe Count5

Note: Geographic validation shows RTT discrepancy (23ms observed vs 125.9ms minimum for reported Washington DC location). This suggests either routing anomalies or geolocation data inconsistency.

---

## RECOMMENDED ACTIONS

Risk Score: 50 (Moderate)

Recommended Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 34.21.87.139 -j DROP

# nftables

nft add rule inet filter input ip saddr 34.21.87.139 drop

# nginx

deny 34.21.87.139;

# pfSense

34.21.87.139/32

# Cloudflare WAF

{"description":"Block 34.21.87.139 β€” IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 34.21.87.139"}}

# AWS WAF

{"Addresses":["34.21.87.139/32"],"Description":"IPDebrief risk 50"}

```

Action Notes:

---

## INTELLIGENCE SUMMARY

IP 34.21.87.139 is a Google Cloud infrastructure endpoint with a moderate risk score. While the IP is not flagged as a known attacker or spam source, it appears on 2 DNSBLs with one high-severity listing. The address lacks active services or open ports, suggesting it may be a reserved or firewall-protected endpoint. Neighborhood analysis indicates low abuse density within the /24 subnet. The geographic validation discrepancy warrants monitoring but does not confirm malicious activity. Current risk assessment supports defensive monitoring with optional blocking depending on organizational threat posture.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVA
CityAshburn
TimezoneAmerica/New_York
Latitude39.04
Longitude-77.49

🏒 Ownership & Registration

OrganizationGoogle LLC
ASNAS396982
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR139.87.21.34.bc.googleusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames139.87.21.34.bc.googleusercontent.com

πŸ” DNS Hygiene

Hygiene Score100% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
8%
11
services
12%
22
ownership
24%
23
reputation
26%
13
geolocation
33%
23
Overall21%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-15 08:44:15 UTC
Last Seen2026-06-28 02:06:03 UTC
Profile Built2026-06-28 20:11:34 UTC
Data FreshnessLive
Signal Types22
Total Observations25
πŸ” 22 signal types Β· 25 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.