# IP Intelligence Briefing: 34.80.184.117/32
## Executive Summary
IP address 34.80.184.117 is a low-risk Google Cloud infrastructure endpoint associated with legitimate Google services. Current threat assessment indicates minimal malicious activity, though the IP appears on one DNS blacklist with high severity rating.
## Profile Overview
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Organization** | Google LLC (ASN 396982) |
| **Network** | GOOGL-2 (34.64.0.0/10) |
| **Geolocation** | Changhua, Taiwan (TW) |
| **Infrastructure Type** | Google Cloud - Single-Service Host |
| **DNS Resolution** | 117.184.80.34.bc.googleusercontent.com |
## Network Classification
- Provider Infrastructure: Google Cloud Platform
- CDN: No
- Vpn/Proxy: No
- Tor Exit: No
- Hosting: No
- Mobile/Residential: No
- Anycast: No
## Service Analysis
- Open Ports: TCP/22 (SSH) - OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
- TLS Certificate: Not configured
- HTTP Service: Not responding
- Email Authentication: SPF and DMARC records present
## Threat Indicators
- Blacklist Status: Listed on 1 of 8 DNSBLs (high severity)
- Abuse Confidence: Not available
- Known Campaigns: None identified
- Campaign Likelihood: None
- Threat Persistence: 0 days observed
## Control Plane Intelligence
- BGP Prefix: 34.80.176.0/20
- Route Stability: Unstable
- DNSSEC: Valid
- DNSBL Listings: 1/8 total lists
- Operator Score: 0.3478 (Basic)
## Observation History
Historical analysis across 21 observations (through August 2026) shows:
- Recent blacklist activity recorded on 2026-08-13 with high severity listing
- Consistent cloud infrastructure classification
- Subnet abuse density rated at 1 (mostly clean)
- No persistent malicious behavior detected
## Neighborhood Assessment
| Metric | Value |
|---|---|
| **Subnet** | 34.80.184.117/24 |
| **Abuse Density** | 1 (Low) |
| **Classification** | Mostly Clean |
| **Threat Siblings** | 1 |
| **Active Siblings** | 1 |
## Relationships
- DNS Associations: 117.184.80.34.bc.googleusercontent.com (primary reverse DNS target)
- Network Affiliations: Multiple references to GOOGL-2 network range
- Total Relationships: 16
## Recommended Actions
Based on the low-risk profile and legitimate cloud infrastructure classification:
- Firewall Rules: No immediate blocking recommended
- Monitoring: Continue standard observation
- Exception: Investigate the single high-severity DNSBL listing if not associated with Google's own infrastructure
- Context: SSH service detected - verify if this is expected for your use case
## Conclusion
This IP address represents legitimate Google Cloud infrastructure with a low-risk profile. The single blacklist listing warrants investigation but does not indicate active malicious behavior. No immediate blocking action is recommended unless organizational policy requires blocking all Google Cloud IPs.
Classification: LOW RISK - Legitimate Cloud Infrastructure
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.64.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 117.184.80.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 117.184.80.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 29% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-02 23:10:27 UTC |
| Last Seen | 2026-08-13 04:27:10 UTC |
| Profile Built | 2026-08-13 04:40:39 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.