# IP Intelligence Briefing: 34.78.84.79/32
## Executive Summary
IP address 34.78.84.79 is a Google Cloud infrastructure endpoint registered under ASN 396982 (Google LLC). The address exhibits moderate risk characteristics with a score of 50, associated with cloud-based infrastructure in the 34.64.0.0/10 block. No active threat indicators were identified, but the IP shows DNSBL presence and moderate neighborhood abuse density warranting monitoring.
## Technical Profile
- Organization: Google LLC
- ASN: 396982
- Network Block: 34.64.0.0/10 (GOOGL-2)
- Geolocation: Belgium (St. Ghislain, BE)
- DNS Resolution: 79.84.78.34.bc.googleusercontent.com
- Infrastructure Type: Google Cloud Provider
- Service Status: Firewalled / No Services Open
- Risk Score: 50 (Moderate Risk)
## Threat Assessment
- Threat Indicators: None identified
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Blacklist Count: 0
- DNSBL Listed: 2 of 8 threat feeds
- Campaign Association: None correlated
## Neighborhood Analysis
The /24 subnet (34.78.84.0/24) shows moderate abuse density (0.5) with mixed reputation distribution:
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 1
- Neighbor IP: 34.78.84.132 (Risk Score: 25, Authority Score: 90)
- Subnet Classification: Mostly Clean
## Historical Observations
Analysis of 17 signal observations indicates stable ownership under Google LLC with no persistent malicious behavior detected. Recent probes (August 2026) confirm consistent geolocation data to Belgium and stable network classification. RTT measurements average 99.2ms from Belgium with plausible geographic validation.
## Recommended Actions
Based on the moderate risk profile and neighborhood context, defensive measures are recommended:
| Platform | Recommended Rule |
|---|---|
| iptables | `iptables -A INPUT -s 34.78.84.79 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 34.78.84.79 drop` |
| nginx | `deny 34.78.84.79;` |
| pfSense | Block 34.78.84.79/32 |
| Cloudflare WAF | Block with expression `ip.src eq 34.78.84.79` |
| AWS WAF | Add rule for address 34.78.84.79/32 |
## Intelligence Narrative
This IP address belongs to Google Cloud infrastructure and is not associated with known malicious campaigns. However, the moderate risk score (50) and presence on DNSBL lists suggest potential policy violations or legitimate traffic that may be flagged by some security systems. The neighborhood shows elevated activity with one threat sibling detected. SOC teams should monitor traffic patterns from this IP for anomalous behavior, particularly if outbound connections exhibit unusual patterns. The IP resolves to a Google-owned domain with proper SPF and DMARC configurations, supporting legitimate cloud service usage.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.64.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 79.84.78.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 79.84.78.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 1/5 domains |
| DMARC | 1/5 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 5 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | kuberneteskubernetes.defaultkubernetes.default.svckubernetes.default.svc.cluster.local |
| Valid From | 2026-08-16T16:41:24+00:00 |
| Valid Until | 2027-08-16T16:43:24+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 00DAFA31A8B045E2877CA26D6FB3023F97 |
| Thumbprint | 16816E3157FB56D9C65149A2FB76A3BA74EFFFE6 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-09 23:08:08 UTC |
| Last Seen | 2026-08-27 10:09:45 UTC |
| Profile Built | 2026-08-29 04:36:00 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.