IP INTELLIGENCE BRIEFING
Target: 34.26.57.145/32
Classification: Moderate Risk - Cloud Infrastructure Asset
Date: Current Analysis Cycle
---
EXECUTIVE SUMMARY
IP 34.26.57.145 is a Google Cloud Platform (GCP) compute instance with a moderate risk score of 40. The address resolves to a Google-owned infrastructure block (GOOGL-2, ASN 396982) and hosts an SSH service. No active threat indicators or known malicious campaigns were identified. The IP is DNSBL listed on 2 of 8 major feeds. No neighboring abuse was detected in the /24 subnet.
---
OWNERSHIP & INFRASTRUCTURE
- Organization: Google LLC
- Network Name: GOOGL-2
- ASN: 396982
- CIDR Block: 34.4.5.0/24
- Infrastructure Type: CloudCompute (Google Cloud Platform)
- Registration Status: Active
- RIR: ARIN
---
GEOLOCATION DATA
- Country: United States (US)
- Region: South Carolina (SC)
- City: Moncks Corner
- Coordinates: 33.21°N, -80.17°W
- Timezone: America/New_York
- Accuracy Radius: 150 km (multi-source inference)
---
NETWORK SERVICES & FINGERPRINTING
- Open Ports: 22/TCP (SSH)
- SSH Banner: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
- DNS PTR: 145.57.26.34.bc.googleusercontent.com
- Reverse DNS Verified: Yes
- Email Authentication: SPF and DMARC records present
---
THREAT INDICATORS
- Risk Score: 40 (Moderate)
- Blacklist Count: 0 active blocklists
- DNSBL Status: Listed on 2 of 8 major feeds
- Abuse Confidence Score: Not available
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Known Campaigns: None identified
---
NETWORK BEHAVIOR & CONTROLS
- Provider Score: 0.0 (Google Cloud infrastructure)
- Authority Score: 0.0 (Standard cloud provider)
- Route Stability: False (route changes detected in last 30 days)
- RPKI State: Not verified
- DNSSEC: Valid
- Operator Score: 0.3478 (Basic)
---
OBSERVATION HISTORY
Total Observations: 17
Most Recent: August 6, 2026
- Geolocation signals confirmed via multi-signal inference
- SSH service banner verified across multiple probes
- No persistent malicious behavior detected
- Threat persistence days: 0
- Is persistently malicious: False
---
RELATIONSHIP GRAPH
- Same Network: GOOGL-2 (multiple associations)
- DNS Associations: 145.57.26.34.bc.googleusercontent.com
- Related Hosts: 3 associated hostname entries
---
SUBNET ANALYSIS
- Subnet: 34.26.57.0/24
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0.0
- Classification: No inherited risk from neighbors
---
RECOMMENDED ACTIONS
Risk Level: 40 (Moderate) β Review recommended, do not block without additional context
Suggested Firewall Rules:
- iptables: `iptables -A INPUT -s 34.26.57.145 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 34.26.57.145 drop`
- nginx: `deny 34.26.57.145;`
- pfSense: `34.26.57.145/32`
- Cloudflare WAF: Block rule with expression `ip.src eq 34.26.57.145`
- AWS WAF: Address set `34.26.57.145/32`
Note: These recommendations are probabilistic. Combine with other threat signals before implementing blocking actions.
---
ANALYST NOTES
This IP represents standard Google Cloud infrastructure with elevated risk classification primarily driven by DNSBL listings and route instability indicators. The moderate risk score (40) warrants monitoring but does not indicate active malicious activity. No correlated IPs or campaign indicators were identified. If this IP appears in threat intelligence or incident logs, investigate the specific context (e.g., outbound connections, scanning activity, or authentication attempts).
Status: Monitor β No immediate threat indicators
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.4.5.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 145.57.26.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 145.57.26.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 1 | 1 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 1 |
| geolocation | 40% | 2 | 3 |
| Overall | 25% | 9 | 11 |
| Data Coherence | Mixed Signals (65%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β High authority score (90) but appears on threat lists (risk 40)
π Observation Timeline π Live
| First Seen | 2026-08-01 01:42:15 UTC |
| Last Seen | 2026-08-13 02:13:25 UTC |
| Profile Built | 2026-08-13 02:25:10 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 26 |
Full dossier details are available via our API.