# IP Intelligence Briefing: 34.60.118.207/32
Classification: Low Risk / Cloud Infrastructure
Risk Score: 25 (Low Risk)
Report Date: [Current Date]
## Executive Summary
IP 34.60.118.207 is a Google Cloud infrastructure endpoint with minimal threat indicators. The IP is associated with Google LLC (ASN 396982) and operates as a single-service host in the GOOGL-2 network block. While the IP shows one DNSBL listing and a low abuse confidence score, overall threat indicators are limited. No active malicious campaigns or known attacker signatures were detected.
## Ownership & Network Context
| Attribute | Value |
|---|---|
| Organization | Google LLC |
| ASN | 396982 (GOOGL-2) |
| Network | 34.4.5.0/24 |
| Geolocation | US, Iowa (Council Bluffs) |
| Infrastructure Type | Cloud Compute (Google Cloud) |
| CIDR Block | 34.60.0.0/16 |
## Service Profile
The IP exposes the following services:
- Port 22/TCP: SSH (OpenSSH_9.6p1 Ubuntu-3ubuntu13.18)
Forward DNS resolution confirmed to: `207.118.60.34.bc.googleusercontent.com`
Reverse DNS: `207.118.60.34.bc.googleusercontent.com`
Domain Association: googleusercontent.com
Email Authentication: SPF and DMARC records present
## Threat Assessment
Current Status: No active threat indicators
- Blacklist Count: 0 (DNSBL listed on 1 feed)
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Campaign Matches: None detected
- Threat Feeds: No active indicators
The single DNSBL listing represents minimal risk exposure. No correlation to known attack campaigns or malicious infrastructure.
## Historical Observations
Analysis of 22 signal observations reveals:
- Persistent Google Cloud classification
- Occasional DNSBL listing activity
- One alienvault-otx threat signal with pulse activity
- No significant risk escalation over observation period
- Route stability: Active changes detected in 30-day window (operator score: 0.3478)
## Neighborhood Analysis
Subnet: 34.60.118.0/24
- Abuse Density: 0
- Neighbor Count: 0
- Classification: Mostly Clean
- Threat Siblings: 1
- High Risk Neighbors: 0
No significant neighboring abuse activity detected in the /24 subnet.
## Recommended Actions
Given the low risk score (25) and Google Cloud infrastructure context:
1. No blocking recommended β IP is legitimate cloud infrastructure
2. Allow with monitoring β SSH access may be legitimate for cloud management
3. Verify against organizational policy β Ensure SSH access aligns with cloud security posture
4. No firewall rules required β No actionable blocking patterns generated
## Conclusion
IP 34.60.118.207 is a low-risk Google Cloud endpoint with no evidence of malicious activity. The infrastructure appears to be legitimate cloud compute services. SOC teams should treat connections as benign cloud traffic unless other threat intelligence sources indicate otherwise.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.4.5.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 207.118.60.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 207.118.60.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 22:22:26 UTC |
| Last Seen | 2026-08-12 23:02:13 UTC |
| Profile Built | 2026-08-12 23:11:48 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.