IPDebrief

34.52.221.98

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Target: 34.52.221.98/32

Classification: Low Risk - Cloud Infrastructure

Date: Current

## EXECUTIVE SUMMARY

IP 34.52.221.98 is a low-risk Google Cloud Compute instance operating from Belgium. The IP shows professional-grade routing characteristics with stable BGP announcements and no persistent malicious indicators. Neighborhood analysis indicates minimal abuse density within the /24 subnet.

## INFRASTRUCTURE PROFILE

Ownership: Google LLC (ASN 396982)

Infrastructure Type: CloudCompute (Google Cloud Platform)

Network Role: Single-Service Host

Geolocation: St. Ghislain, Walloon Region, Belgium (BE)

CIDR Block: 34.52.221.0/24

## NETWORK CHARACTERISTICS

BGP Origin: 34.52.128.0/17

AS Path: 57866 โ†’ 15169 โ†’ 396982

RPKI Validation: Valid

Route Stability: Stable (0 route changes in 30 days)

Operator Score: 0.8696 (Professional)

DNSBL Status: Listed on 1 of 8 threat feeds (non-critical)

Resolved Hostnames: 98.221.52.34.bc.googleusercontent.com

DNS Forward Confirmation: Confirmed

Email Authentication: SPF and DMARC records present

## SERVICE EXPOSURE

Open Ports:

TLS/TLS Certificate: Not deployed

HTTP Services: No HTTP activity detected

## THREAT ASSESSMENT

Overall Risk Score: 15/100 (Low Risk)

Abuse Confidence Score: Not applicable

Known Attacker Status: False

Spam Source Status: False

Tor Exit Node: False

Threat Persistence: None observed

Campaign Correlation: None detected

Key Risk Indicators:

## OBSERVATION HISTORY

Total Observations: 35 signals recorded

Recent Activity: Signals observed through June 2026

Operator Classification: Professional (consistent routing behavior)

Geolocation Consensus: Validated across multiple sources

Malicious Activity Timeline: No persistent threats detected

## NETWORK RELATIONSHIPS

Total Relationships: 308 associations identified

DNS Associations: Multiple hostnames under googleusercontent.com domain

Network Affiliation: GOOGL-2 network segment

Certificate Associations: None

## SUBNET ANALYSIS (34.52.221.0/24)

Abuse Density: 1 (Low)

Classification: Mostly Clean

Inherited Risk Score: 2

Active Siblings: 1

Threat Siblings: 1 (low-severity)

## RECOMMENDATIONS FOR SOC ANALYSTS

1. Monitor SSH Traffic: Standard cloud workload behavior; verify if port 22 usage aligns with expected Google Cloud services

2. DNSBL Verification: Investigate the single DNSBL listing to determine severity and source

3. Baseline Comparison: Use as reference for legitimate Google Cloud Compute traffic patterns

4. No Immediate Action Required: IP exhibits characteristics of legitimate cloud infrastructure

## CONCLUSION

This IP address represents standard Google Cloud Platform infrastructure with professional routing characteristics and no active malicious indicators. The single threat sibling and minimal DNSBL listing warrant contextual review but do not indicate immediate threat. SOC analysts should treat this as low-priority cloud infrastructure with standard monitoring protocols.

---

*Generated by IPDebrief Intelligence Platform*

*Data Source: IPDebrief® Intelligence Database*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ง๐Ÿ‡ช Belgium
RegionWAL
CitySt. Ghislain
TimezoneEurope/Brussels
Latitude50.45
Longitude3.82

๐Ÿข Ownership & Registration

OrganizationGoogle LLC
ASNAS396982
Network Nameโ€”
CIDR Block34.52.128.0/17
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR98.221.52.34.bc.googleusercontent.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnames98.221.52.34.bc.googleusercontent.com

๐Ÿ” DNS Hygiene

Hygiene Score100% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 r4

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
21%
24
routing
24%
45
services
20%
23
ownership
22%
34
reputation
26%
13
geolocation
32%
23
Overall24%1422
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionHigh (100%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:16 UTC
Last Seen2026-06-27 04:39:16 UTC
Profile Built2026-06-28 04:45:45 UTC
Data FreshnessLive
Signal Types32
Total Observations39
๐Ÿ” 32 signal types ยท 39 observations collected
This report is generated from 32+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.