# IP Intelligence Briefing: 35.185.52.64/32
## Executive Summary
Intellectual analysis of 35.185.52.64 reveals a Google Cloud infrastructure address with moderate risk classification (Score: 50). The IP exhibits no active threat indicators but demonstrates DNSBL presence and basic operator scoring. No open services or ports detected; the address is classified as Google Cloud infrastructure.
## Infrastructure Profile
Ownership: Google LLC (ASN: AS396982) | Netname: GOOGLE-CLOUD
CIDR Block: 35.184.0.0/13
Geolocation: North Charleston, SC, US (Coordinates: 33.84, -81.16)
DNS Resolution: 64.52.185.35.bc.googleusercontent.com (googleusercontent.com)
PTR Hostname: 64.52.185.35.bc.googleusercontent.com
## Risk Assessment
- Overall Risk Score: 50 (Moderate Risk)
- Abuse Confidence Score: Not reported
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listings: 2 of 8 total lists
- Control Plane Operator Score: 0.3478 (Basic)
- Route Stability: Not stable (route changes detected within 30-day window)
## Network Exposure
Services: None detected (firewalled/no services)
Open Ports: None
TLS/Certificates: None
HTTP Banner: None
Infrastructure Type: Unknown (classified as Google Cloud provider)
## Historical Activity
Observation history spans 20 signals from 2026-07-31 through 2026-08-06. Analysis indicates:
- No persistent malicious activity detected
- Zero ownership changes recorded
- No threat persistence days observed
- Threat observation count: 0
- Most recent signals (August 6) show basic operator classification with 0.3478 score
## Neighborhood Context
Subnet: 35.185.52.64/24
Abuse Density: 0
Classification: Clean
Active Siblings: 0
Threat Siblings: 0
Total Siblings: 1
No neighboring IPs within the /24 subnet exhibit abuse activity.
## Relationship Graph
Primary associations limited to:
- Same Network: GOOGLE-CLOUD
- DNS Associations: 64.52.185.35.bc.googleusercontent.com (repeated)
No external organizational or certificate relationships detected.
## Recommended Actions
Risk Score: 50
Provider Classification: Google Cloud
Recommended Firewall Rules:
- iptables: `iptables -A INPUT -s 35.185.52.64 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 35.185.52.64 drop`
- nginx: `deny 35.185.52.64;`
- pfSense: `35.185.52.64/32`
- Cloudflare WAF: Block IP (risk score 50)
- AWS WAF: 35.185.52.64/32
## Intelligence Narrative
The IP address 35.185.52.64 is a Google Cloud infrastructure endpoint located in North Charleston, South Carolina. While classified as moderate risk, the address demonstrates no active threat indicators or malicious behavior patterns. The moderate risk classification stems from DNSBL listings (2 of 8) and route instability rather than confirmed malicious activity. No open services or ports are exposed, reducing direct exploitation vectors. Historical monitoring confirms absence of persistent malicious behavior. The subnet exhibits clean classification with zero abuse density, indicating this IP's risk profile may be elevated relative to its peer infrastructure. SOC analysts should note that the moderate risk score warrants monitoring but does not indicate confirmed compromise or active threat activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.184.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 64.52.185.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 64.52.185.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 13 |
| Data Coherence | Mostly Consistent (85%) β 1 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 22:50:21 UTC |
| Last Seen | 2026-08-13 00:16:51 UTC |
| Profile Built | 2026-08-13 00:19:38 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.