# IP Intelligence Briefing: 34.38.105.20
Classification: Moderate Risk | Date: 2026-08-13
Analyst: IPDebrief Intelligence Team
## Executive Summary
IP address 34.38.105.20 registered to Google LLC (ASN 396982, netname GOOGL-2) presents a moderate risk profile with a score of 40. The address operates within Google Cloud infrastructure with geolocation data indicating Brussels, Belgium. No active threat indicators were detected during analysis, though the IP maintains presence on 2 of 8 DNS blacklists.
## Profile Characteristics
Ownership & Classification:
- Provider: Google LLC (ASN 396982)
- Network: 34.38.0.0/16 (GOOGL-2)
- Infrastructure Type: Cloud provider environment
- DNS: Resolves to 20.105.38.34.bc.googleusercontent.com
Geolocation Data:
- Country: Belgium (BE)
- City: Brussels
- Geo-Validation: Consensus confirmed across multiple sources; ICMP validation blocked
Threat Indicators:
- Blacklist Count: 0
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Known Campaigns: None detected
Network Services:
- Open Ports: None detected
- Service Status: Firewalled / No Services
- DNSSEC: Valid
- CAA Records: Present
## Temporal Analysis
Historical observation data shows 20 signal observations collected during 2026-08-13. The IP demonstrates stable ownership with no recorded changes. Threat persistence metrics show zero persistent malicious activity. Traceroute analysis completed 30 hops to target, with no anomalies in routing path.
## Neighborhood Assessment
Subnet analysis for 34.38.105.0/24 reveals:
- Total Siblings: 0
- Abuse Density: 0
- Threat Siblings: 0
- High/Medium/Low Risk Neighbors: None detected
The IP exists in isolation within its /24 subnet with no neighboring addresses flagged for abuse.
## Relationship Graph
Seven relationships identified:
- DNS Associations: Multiple entries pointing to bc.googleusercontent.com
- Network Associations: GOOGL-2 network (34.38.0.0/16)
No external organization or certificate associations detected beyond Google infrastructure.
## Recommended Actions
Despite no specific threat indicators, the moderate risk score warrants standard defensive measures:
Firewall Recommendations:
- iptables: `iptables -A INPUT -s 34.38.105.20 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 34.38.105.20 drop`
- Cloudflare WAF: Block with expression `ip.src eq 34.38.105.20`
- AWS WAF: Add `34.38.105.20/32` to blacklist
SOC Analyst Notes:
The IP presents a moderate risk profile (40/100) attributable to Google Cloud infrastructure. While no active malicious indicators were detected, the presence on DNS blacklists warrants monitoring. The address should be evaluated against organizational threat contextβlegitimate Google Cloud workloads may legitimately appear on certain blocklists. Correlation with other security signals recommended before implementing blocking rules.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.4.5.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 20.105.38.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 20.105.38.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 7 |
| routing | 22% | 1 | 3 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 40% | 1 | 23 |
| geolocation | 27% | 2 | 3 |
| Overall | 28% | 10 | 41 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-12 06:12:35 UTC |
| Last Seen | 2026-09-11 15:49:09 UTC |
| Profile Built | 2026-09-11 20:18:31 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 79 |
Full dossier details are available via our API.