IPDebrief

34.56.229.114

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 34.56.229.114/32

## Executive Summary

IP address 34.56.229.114 operates within Google Cloud infrastructure with an overall low-risk profile (risk score: 25). The IP is associated with Google LLC (ASN 396982) and functions as a web server/hosting service. While the IP shows minimal malicious activity, it is listed on 1 of 8 DNS blacklists and is linked to a single threat sibling in its /24 neighborhood.

## Risk Assessment

Risk Score: 25 (Low Risk)

Reputation: Low Risk

Abuse Confidence: Not elevated

Blacklist Status: 1/8 DNSBL entries

Classification: CloudCompute / Web Server

## Infrastructure Profile

## Network Services

PortProtocolServiceStatus
80TCPHTTPOpen
443TCPHTTPSOpen
22TCPSSHOpen

TLS Certificate: Let's Encrypt (CN=demos.biwares.com)

Server Banner: Apache/2.4.67 (Debian)

DNS Records: googleusercontent.com ptr hostname

## Threat Indicators

## Neighborhood Analysis

Subnet: 34.56.229.114/24

## Historical Observations (27 records)

Recent observations (2026-06-21) confirm:

## Relationships

## Recommended Actions

1. Monitoring: Continue monitoring for changes in blacklist status or new threat indicators.

2. SSH Exposure: The open SSH port (22) on a public-facing cloud instance warrants review for unauthorized access attempts.

3. DNSBL Investigation: Investigate the single DNSBL listing to understand the listing reason and determine if action is required.

4. Geolocation Validation: Note RTT/geo discrepancy (7218.7km vs minimum possible 144.4ms) indicates potential geolocation inaccuracy.

5. Certificate Review: TLS certificate subject (demos.biwares.com) may warrant validation against legitimate business use.

## Conclusion

This IP represents a standard Google Cloud web hosting instance with minimal threat indicators. While not actively malicious, the open SSH port and DNSBL listing warrant standard defensive monitoring. No immediate blocking is recommended; however, the SSH exposure should be evaluated for necessity on a publicly accessible cloud instance.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionIA
CityCouncil Bluffs
TimezoneAmerica/Chicago
Latitude41.26
Longitude-95.85

🏒 Ownership & Registration

OrganizationGoogle LLC
ASNAS396982
Network NameGOOGL-2
CIDR Block34.4.5.0/24
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR114.229.56.34.bc.googleusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames114.229.56.34.bc.googleusercontent.com

πŸ” DNS Hygiene

Hygiene Score100% (Excellent)
SPF2/2 domains
DMARC1/2 domains
FCrDNSVerified
DNSSECValid
CAAPresent
Domains Checked2 domains

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache/2.4.67 (Debian)
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.2

πŸ” TLS Certificate

πŸ”’
CN=demos.biwares.com
Issued by CN=E8, O=Let's Encrypt, C=US
Self-signed: No
SANsdemos.biwares.com
Valid From2026-05-17T05:34:37+00:00
Valid Until2026-08-15T05:34:36+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number06A83B78A61CD7FADD2B81A1774413485947
ThumbprintEE8F75007C2B927BA4C4242F927EF08AA16A49AF

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
27%
23
services
27%
23
ownership
30%
34
reputation
22%
13
geolocation
27%
23
Overall27%1219
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-30 17:03:40 UTC
Last Seen2026-06-29 07:56:49 UTC
Profile Built2026-06-29 08:04:57 UTC
Data FreshnessLive
Signal Types27
Total Observations28
πŸ” 27 signal types Β· 28 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.