# IP Intelligence Briefing: 34.72.22.196
Classification: LOW RISK / CLOUD INFRASTRUCTURE
Date Generated: 2026-06-25
---
## Executive Summary
IP 34.72.22.196 is a low-risk Google Cloud infrastructure endpoint with no active threat indicators. The address resolves to legitimate cloud hosting infrastructure and shows no evidence of malicious activity, spam, or known attacker behavior. No immediate defensive action required.
---
## Risk Profile
| Metric | Value |
|---|---|
| Risk Score | 25 (Low Risk) |
| Provider Score | 0 |
| Authority Score | 0 |
| Stability Score | 0 |
| Abuse Confidence | Not applicable |
Key Assessment: The IP demonstrates stable Google Cloud infrastructure characteristics with minimal threat exposure.
---
## Ownership & Infrastructure
- Organization: Google LLC
- ASN: 396982
- Infrastructure Type: CloudCompute
- Network Role: Provider / Cloud Hosting
- Service Purpose: Firewalled / No Services
- Registration: ARIN Registry
Status: Legitimate cloud provider infrastructure with no anomalous ownership patterns.
---
## Geolocation
- Country: United States (US)
- Region: Iowa (IA)
- City: Council Bluffs
- Coordinates: 41.26°N, 95.86°W
- Timezone: America/Chicago
Note: Geolocation validation shows some RTT discrepancies (58ms observed vs 144.4ms minimum possible for distance), which is consistent with cloud provider routing patterns.
---
## Threat Indicators
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Matches: 0
- Known Campaigns: None detected
Status: Clean threat profile with no malicious indicators.
---
## Network Analysis
DNS Resolution
- PTR Hostname: 196.22.72.34.bc.googleusercontent.com
- Forward Resolution: Confirmed
- DNS Type: Reverse DNS to Google domain
Services
- Open Ports: None detected
- HTTP/TLS: No active services
- Banner Analysis: No detectable services
Control Plane
- BGP Prefix: 34.72.16.0/20
- Route Stability: Inconsistent (flagged as not stable)
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 lists (likely false positive)
---
## Relationship Graph
55 relationships identified:
- Multiple Same Network associations (GOOGL-2)
- DNS associations to bc.googleusercontent.com hostnames
- Standard Google Cloud network topology
Status: Normal cloud provider relationship patterns.
---
## Neighborhood Assessment (34.72.22.0/24)
- Abuse Density: 0%
- Classification: Clean
- Active Siblings: 1 (this IP)
- Threat Siblings: 0
Status: Subnet shows no abuse concentration.
---
## Observation History
Total Observations: 24 signals tracked
Recent Activity (2026-06-25):
- Cloud infrastructure classification confirmed
- No malicious signal patterns
- Consistent Google Cloud provider identification
- No threat persistence observed
Threat Persistence Days: 0
Is Persistently Malicious: No
---
## Security Actions & Recommendations
Recommended Actions: None
Rationale: The IP address represents legitimate Google Cloud infrastructure with low risk score (25). No firewall rules or blocking actions recommended. Standard monitoring practices apply.
Monitoring Guidelines:
- No immediate blocking required
- Monitor for any behavioral changes in outbound traffic
- Standard log review for cloud egress patterns
---
## Final Assessment
IP 34.72.22.196 is classified as a low-risk Google Cloud infrastructure endpoint. The address shows standard cloud provider behavior with no malicious indicators, no active threat campaigns, and a clean neighborhood profile. No defensive action required beyond standard monitoring practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 196.22.72.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 196.22.72.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-08 11:10:32 UTC |
| Last Seen | 2026-06-27 13:14:44 UTC |
| Profile Built | 2026-06-28 07:20:09 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 30 |
Full dossier details are available via our API.