# IP Intelligence Briefing: 35.187.248.175/32
Classification: LOW RISK β Legitimate Cloud Infrastructure
Risk Score: 25/100
Report Date: Current
## Executive Summary
IP address 35.187.248.175 belongs to Google LLC infrastructure and is classified as low-risk. The address resolves to Google Cloud Platform hosting (ASN 396982) with geolocation data indicating Singapore (SG). No active threat indicators, blacklistings, or malicious campaigns were observed. Recommended classification for SOC analysts: ALLOW β No blocking required.
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 35.187.248.175/32 |
| **Organization** | Google LLC |
| **ASN** | 396982 |
| **Infrastructure Type** | CloudCompute |
| **Network Provider** | Google Cloud |
| **Geolocation** | Singapore (1.35°N, 103.82°E) |
| **CIDR Block** | 35.187.224.0/19 |
| **Risk Score** | 25 |
| **Abuse Confidence** | Not applicable (clean) |
## DNS & Network Analysis
- PTR Record: 175.248.187.35.bc.googleusercontent.com
- Forward Resolution: Confirmed to googleusercontent.com domain
- Email Authentication: SPF and DMARC records present
- Open Ports: None detected
- HTTP Services: No active web services
- TLS Certificates: None exposed
The DNS hostname pattern (bc.googleusercontent.com) indicates Google Cloud CDN/hosting infrastructure, commonly used for content delivery and static asset hosting.
## Threat Intelligence
- Blacklist Status: Clean (0 blacklistings)
- Threat Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Vulnerability Scans: None recorded
- Historical Threat Persistence: 0 days
## Observation History
21 signal observations recorded. Recent activity (2026-06-20) shows consistent infrastructure classification:
- ASN: GOOGLE-CLOUD-PLATFORM (Google LLC, US)
- Geolocation inference: Singapore (confidence 0.56)
- Network role: CloudCompute (confidence 0.90)
- Operator score: 0.3478 (Basic operator)
The IP demonstrates stable ownership with no recent changes, consistent with legitimate cloud hosting operations.
## Neighborhood Analysis
Subnet: 35.187.248.175/24
- Classification: Mostly clean
- Abuse Density: 0
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
The /24 neighborhood exhibits minimal threat activity. The single threat sibling identified may warrant monitoring but does not indicate compromised infrastructure for 35.187.248.175.
## Relationship Graph
73 relationships identified:
- DNS Associations: Multiple hostname entries pointing to googleusercontent.com
- Network Associations: GOOGLE-CLOUD network designation
- Same Network: Google Cloud Platform infrastructure
All relationships align with expected Google Cloud infrastructure patterns.
## Recommended Security Actions
Status: No blocking required
- Firewall Rules: None recommended
- WAF Rules: None required
- Monitoring Priority: Low
The IP address should be allowed through standard network security controls. No firewall rules or WAF policies are necessary due to the low-risk classification and legitimate cloud infrastructure identity.
## Analyst Notes
This IP represents standard Google Cloud Platform infrastructure. The googleusercontent.com domain is used for Google-hosted content and services. SOC analysts may observe this IP from clients using Google Cloud services. No defensive action is required beyond normal logging and monitoring.
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 175.248.187.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 175.248.187.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 23% | 1 | 2 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-23 06:22:32 UTC |
| Last Seen | 2026-06-28 20:38:45 UTC |
| Profile Built | 2026-06-29 02:40:51 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.