# IP INTELLIGENCE BRIEFING
Target: 35.187.79.97/32
Classification: Google Cloud Infrastructure | Low Risk
Date: Current Analysis Cycle
---
## EXECUTIVE SUMMARY
IP 35.187.79.97 is a Google Cloud Platform (GCP) infrastructure address operating as a single-service cloud host. Risk assessment indicates LOW RISK (score: 25/100) with no active threat indicators, zero blacklist listings, and a clean neighborhood profile. The IP shows stable ownership and operational history within Google's Belgian infrastructure region.
---
## OWNERSHIP & INFRASTRUCTURE
- Provider: Google LLC (ASN 396982)
- Network: GOOGLE-CLOUD (35.184.0.0/13)
- Infrastructure Type: Cloud Compute
- Registration: RIR: ARIN
- Network Role: Single-Service Host / Hosted Infrastructure
---
## GEOLOCATION DATA
- Country: Belgium (BE)
- Region: Wallonia (WAL)
- City: St. Ghislain
- Coordinates: 50.45°N, 3.82°E
- Geo Validation: ICMP blocked - unable to validate (ICRT: 236.8 km)
- DNS PTR: 97.79.187.35.bc.googleusercontent.com
---
## THREAT ASSESSMENT
| Indicator | Status |
|---|---|
| Risk Score | 25 (Low Risk) |
| Abuse Confidence | Not applicable |
| Blacklist Count | 0 |
| Known Attacker | False |
| Spam Source | False |
| Tor Exit Node | False |
| Known Campaigns | None |
| Pulsedive Risk | N/A |
Control Plane:
- Operator Score: 0.5652 (Moderate)
- Route Stability: Stable (no changes in last 30 days)
- DNSSEC: Valid
- IRR Consistency: Not evaluated
- DNSBL Listed: 1 of 8 lists
---
## NETWORK NEIGHBORHOOD
Subnet: 35.187.79.0/24
Abuse Density: 0 (Low)
Classification: mostly_clean
Active Siblings: 2
Neighbor Risk Profile:
- 35.187.79.243: Risk 25 / Authority 90
---
## OBSERVATION HISTORY (28 Signals)
Recent activity patterns indicate:
- June 21, 2026: ASN resolution confirmed (GOOGLE-CLOUD-PLATFORM), operator score assessed as Moderate
- June 29, 2026: Geolocation signals consistent (St. Ghislain, BE)
- Threat Persistence: 0 days
- Ownership Changes: 0
- Threat Observation Count: 1 (historical)
- Persistence Status: Not persistently malicious
---
## DNS & SERVICE ENDPOINTS
- DNS Resolution: Forward confirmed (googleusercontent.com)
- Open Ports: TCP/22 (SSH - OpenSSH_10.0)
- TLS Certificate: None detected
- HTTP Service: None detected
- Email Auth: SPF and DMARC records present
---
## RELATIONSHIP GRAPH
55 relationships identified:
- Multiple network associations to GOOGLE-CLOUD
- DNS hostname associations: 97.79.187.35.bc.googleusercontent.com
- No suspicious entity correlations detected
---
## RECOMMENDED SECURITY ACTIONS
Risk Score: 25 (Low Risk)
Actionable Recommendations: None
Firewall/Blocking Considerations:
- No immediate blocking recommended
- Standard allow-listing for Google Cloud egress permitted
- Monitor for anomalous outbound connections from internal systems to this IP
---
## INTELLIGENCE NOTES FOR SOC ANALYSTS
1. Legitimate Infrastructure: This IP operates as Google Cloud infrastructure. Traffic should be permitted per organizational policy for cloud services.
2. Low Threat Profile: No threat indicators, zero blacklist matches, and clean neighborhood profile.
3. SSH Exposure: Port 22 is open (typical for cloud infrastructure). Monitor for brute force attempts but do not block without additional context.
4. Historical Context: Single historical threat observation with no persistence. IP is not currently classified as malicious.
5. Monitoring Priority: Low. Standard traffic baseline monitoring appropriate.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.184.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 97.79.187.35.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 97.79.187.35.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.0 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 30% | 3 | 4 |
| reputation | 22% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 26% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-28 06:16:27 UTC |
| Last Seen | 2026-06-29 05:13:08 UTC |
| Profile Built | 2026-06-29 05:17:47 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 28 |
Full dossier details are available via our API.