# IP Intelligence Briefing: 34.24.128.94/32
## Executive Summary
Intellectual analysis indicates 34.24.128.94 is a Google Cloud infrastructure address with moderate risk characteristics. The IP resolves to legitimate Google Cloud DNS infrastructure but exhibits some risk indicators warranting monitoring. No active malicious activity confirmed at time of analysis.
## Asset Profile
| Attribute | Details |
|---|---|
| **IP Address** | 34.24.128.94/32 |
| **Risk Score** | 50 (Moderate Risk) |
| **Provider** | Google LLC (ASN 396982) |
| **Organization** | GOOGL-2 |
| **Geolocation** | South Carolina, North Charleston, US |
| **Classification** | Firewalled / No Services |
| **Network Role** | Google Cloud Provider |
| **DNS Target** | 94.128.24.34.bc.googleusercontent.com |
## Threat Assessment
Current Threat Indicators: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listings: 2 of 8 total lists
- Threat Feeds: Empty
- Campaign Associations: None identified
Network Characteristics:
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Banner: None
- Service Purpose: Firewalled / No Services
Control Plane:
- BGP Prefix: 34.24.0.0/16
- Route Stability: False
- DNSSEC Validation: Valid
- RPKI State: Not available
- Operator Score: 0.3478 (Basic)
## Historical Observations
Analysis captured 23 signal observations. Key temporal indicators:
- Abuse Density: 1 (subnet level)
- Inherited Risk: 2
- Subnet Classification: Mostly clean
- Threat Persistence: 0 days
- Observation Count: 0 active threats
Recent signals (2026-08-06) show consistent benign characteristics with no escalation patterns. The IP has not been observed as persistently malicious.
## Network Relationships
DNS Associations:
- 94.128.24.34.bc.googleusercontent.com (multiple entries)
Network Relationships:
- Multiple associations with GOOGL-2 network (21 relationship entries)
- All relationships indicate same network classification
## Neighborhood Analysis
Subnet: 34.24.128.94/24
- Abuse Density: 1
- Classification: Mostly clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Inherited Risk: 2
Risk distribution across neighborhood shows balanced profile with no high-risk neighbors identified.
## Recommended Actions
Based on risk profile, the following firewall rules are recommended:
iptables:
```bash
iptables -A INPUT -s 34.24.128.94 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 34.24.128.94 drop
```
nginx:
```nginx
deny 34.24.128.94;
```
pfSense:
```
34.24.128.94/32
```
Cloudflare WAF:
```json
{
"description": "Block 34.24.128.94 β IPDebrief risk score 50",
"action": "block",
"filter": {"expression": "ip.src eq 34.24.128.94"}
}
```
AWS WAF:
```json
{
"Addresses": ["34.24.128.94/32"],
"Description": "IPDebrief risk 50"
}
```
## Intelligence Narrative
The target IP 34.24.128.94 belongs to Google Cloud's infrastructure network. While the address resolves to legitimate Google Cloud DNS infrastructure (googleusercontent.com), the moderate risk score of 50 combined with 2 DNSBL listings suggests the address may be associated with some level of suspicious activity. However, no direct threat indicators (malware, spam, known attacker) were detected.
The neighborhood analysis shows the /24 subnet as "mostly clean" with low abuse density (1). The 1 threat sibling represents minimal correlation risk. Historical data shows no persistent malicious behavior patterns.
Recommendation: Monitor for any activity patterns. Given the Google Cloud infrastructure nature and moderate risk profile, the IP may warrant blocking in strict security environments, but should not be treated as a confirmed malicious address. Consider whitelisting if traffic is expected from this range.
---
*Intelligence prepared by IPDebrief threat analysis system. All data based on observed network signals and threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.4.5.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 94.128.24.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 94.128.24.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 29% | 10 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 17:12:06 UTC |
| Last Seen | 2026-08-13 00:58:24 UTC |
| Profile Built | 2026-08-13 01:22:38 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 31 |
Full dossier details are available via our API.