# INTELLIGENCE BRIEFING: IP 35.187.55.217/32
Classification: LOW RISK
Date: 2026-07-29
Analyst: IPDebrief Intelligence
---
## EXECUTIVE SUMMARY
IP 35.187.55.217 operates on Google Cloud infrastructure with a low-risk profile (score: 25/100). The address is associated with legitimate cloud hosting services and shows no indicators of malicious activity. No immediate threat actions required; standard monitoring recommended.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| Organization | Google LLC |
| ASN | 396982 |
| Network | GOOGLE-CLOUD (35.184.0.0/13) |
| RIR | ARIN |
| IP Classification | Cloud Infrastructure |
The address is registered under Google LLC's cloud network. Geographic data indicates St. Ghislain, Belgium (50.45°N, 3.82°E), though some historical signals show US-based coordinates (94043, California), suggesting multi-region routing or datacenter distribution.
---
## NETWORK PROFILE
Open Services:
- Port 443/TCP: HTTPS (Web Server)
DNS Resolution:
- PTR: 217.55.187.35.bc.googleusercontent.com
- Forward Confirmed: Yes
- Hosted Domain: googleusercontent.com
TLS Configuration:
- Certificate Issuer: CN=8384f680-b94b-4983-969e-9a5bc62eee19
- Subject: CN=35.233.122.161
- SANs: kubernetes, kubernetes.default, kubernetes.default.svc
- Self-Signed: No
- HTTP Version: 2.0
The TLS certificate indicates Kubernetes service infrastructure, typical for Google Cloud Platform deployments.
---
## THREAT ASSESSMENT
Risk Indicators:
- Risk Score: 25 (Low Risk)
- Abuse Confidence: None detected
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane:
- Route Stability: False (route changes detected)
- DNSSEC Valid: Yes
- CAA Records: Present
- DNSBL Listed: 1 of 8 lists
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: No
---
## OBSERVATION HISTORY
Total observations: 21 (most recent: 2026-07-29)
Recent Signals:
- HTTP Response: 403 Forbidden (rate-limiting or access control in place)
- HTTP/2.0: Enabled
- Content Security Policy: Not present
- HSTS: Not present
Geographic Signals:
- Primary: Belgium (50.45°N, 3.82°E)
- Secondary: United States (94043, CA)
- ICMP Validation: Blocked (unable to validate)
- Geo Plausibility: Validated
---
## NETWORK NEIGHBORHOOD
Subnet: 35.187.55.0/24
- Abuse Density: 0
- Classification: Clean
- Threat Siblings: 0
- Active Siblings: 0
- Total Siblings: 1
The /24 subnet shows no abuse activity and is classified as clean. No neighboring IPs present threat indicators.
---
## RELATIONSHIPS
| Type | Target | Value |
|---|---|---|
| DNS Association | hostname | 217.55.187.35.bc.googleusercontent.com |
| Same Network | network | GOOGLE-CLOUD |
---
## SECURITY ACTIONS & RECOMMENDATIONS
Current Risk Level: LOW
Recommended Actions: None
Firewall Rules: Not required
The low risk score, clean neighborhood, and legitimate cloud infrastructure classification indicate no immediate blocking is necessary. Standard ingress/egress filtering and logging recommended.
---
## INTELLIGENCE CONCLUSION
IP 35.187.55.217 represents a legitimate Google Cloud web server endpoint. The 403 Forbidden responses suggest access control mechanisms are in operation. No threat indicators detected across all signal types. No correlation with known campaigns or malicious infrastructure.
Threat Status: CLEAN
Action Required: MONITOR
Confidence Level: HIGH
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.184.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 217.55.187.35.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 217.55.187.35.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 06:47:25 UTC |
| Last Seen | 2026-08-12 15:42:26 UTC |
| Profile Built | 2026-08-12 15:57:21 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 27 |
Full dossier details are available via our API.