# IP Intelligence Briefing: 34.75.233.249/32
## Executive Summary
IP address 34.75.233.249 is a legitimate Google Cloud infrastructure endpoint located in South Carolina, US. The IP presents a moderate risk score of 65 with no active malicious threat indicators. While the IP shows evidence of DNSBL listing and geolocation inconsistencies, these are consistent with large-scale cloud infrastructure patterns rather than malicious activity.
## Technical Profile
- Owner/Operator: Google LLC (ASN 396982, Netname: GOOGL-2)
- Infrastructure Type: CloudCompute (Google Cloud Platform)
- CIDR Block: 34.64.0.0/10
- Registered Network: GOOGL-2 (Google LLC)
- Geolocation: North Charleston, South Carolina, US
- DNS Resolution: 249.233.75.34.bc.googleusercontent.com (Forward confirmed)
- Open Services: TCP/22 (SSH) - OpenSSH 9.6p1 Ubuntu-3ubuntu13.18
## Risk Assessment
Overall Risk Score: 65 (Moderate Risk)
Key Risk Indicators:
- Listed on 3 out of 8 DNSBLs (abuseConfidenceScore: null)
- RTT validation failure: Claimed latency 39ms vs minimum possible 139.2ms for reported location
- Operator score: 0.3478 (Basic classification)
Mitigating Factors:
- No known malicious campaigns associated
- Not flagged as known attacker, Tor exit node, spam source, or proxy
- No blacklisted threat indicators in primary threat feeds
- Stable ownership within Google infrastructure
## Neighborhood Analysis
Subnet 34.75.233.0/24 shows:
- Abuse Density: 0 (Clean)
- Active Siblings: 0
- Threat Siblings: 0
- Classification: Clean
No sibling IPs in the /24 subnet are flagged as threats, indicating this IP operates in a benign cloud environment.
## Historical Observations
23 total observations recorded. Recent activity (as of 2026-08-13) shows:
- Consistent DNS association signals
- Operator scoring fluctuations between 0.28-0.40
- Multiple DNSBL listing events with high severity flags
- Geographic signals inferred to Moncks Corner, SC (confidence: 0.28)
- Persistent RTT validation anomalies
## Network Relationships
- Primary association: GOOGL-2 network (Google infrastructure)
- DNS hostname: 249.233.75.34.bc.googleusercontent.com
- 13 total relationship links detected
- No external organization associations beyond Google ecosystem
## Recommended Actions
No immediate firewall blocking required. The IP is legitimate Google Cloud infrastructure. Recommended SOC handling:
1. Allow inbound traffic on established ports with standard logging
2. Monitor for anomalous outbound connections from internal hosts to this IP
3. No need for aggressive blocking or rate limiting on this endpoint
Note: If traffic anomalies are observed, investigate at the endpoint level rather than blocking the IP, as this is legitimate cloud infrastructure that may appear in threat logs due to false-positive classifications common in large cloud environments.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.64.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 249.233.75.34.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 249.233.75.34.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 42% | 2 | 3 |
| Overall | 29% | 10 | 17 |
| Data Coherence | Mixed Signals (65%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β High authority score (90) but appears on threat lists (risk 40)
π Observation Timeline π Live
| First Seen | 2026-07-30 23:20:37 UTC |
| Last Seen | 2026-08-13 01:15:10 UTC |
| Profile Built | 2026-08-13 01:23:41 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 23 |
Full dossier details are available via our API.