# INTELLIGENCE BRIEFING: 35.190.166.117/32
Classification: Threat Intelligence Report
Target: 35.190.166.117/32
Analysis Date: 2026-08-06
Status: High Risk Classification with Cloud Infrastructure Context
## EXECUTIVE SUMMARY
Target IP 35.190.166.117 is a Google Cloud Compute instance located in North Charleston, South Carolina, USA (ASN 396982). The IP carries a High Risk classification (Risk Score: 80) driven primarily by DNSBL listings (4 of 8 total lists). No active threat indicators, campaigns, or malicious activity have been observed. The IP appears to be a legitimate cloud infrastructure endpoint with no open services.
## NETWORK IDENTIFICATION
| Attribute | Value |
|---|---|
| Organization | Google LLC |
| ASN | 396982 |
| CIDR Block | 35.184.0.0/13 |
| Infrastructure Type | CloudCompute |
| Location | US, South Carolina, North Charleston |
| Network Classification | Cloud / Hosting |
## RISK PROFILE ANALYSIS
Risk Score: 80/100 (High Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
Primary Risk Factors:
- 4 DNSBL listings across 8 total blacklist sources
- Control plane operator label: "Basic"
- Route stability flagged as unstable (isRouteStable: false)
Risk Mitigating Factors:
- No threat indicators detected
- No known attacker, spam source, or Tor exit node activity
- No blacklist entries for abuse confidence
- Known attacker flags: Clear
## NETWORK NEIGHBORHOOD ANALYSIS
Subnet: 35.190.166.117/24
- Abuse Density: 0% (Clean classification)
- Total Sibling IPs: 1
- Active Siblings: 0
- Threat Siblings: 0
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 0
The /24 subnet demonstrates no malicious activity from neighboring addresses, indicating this IP's risk profile is isolated to the specific endpoint.
## OBSERVATION HISTORY (Last 20 Observations)
Recent signal activity captured on 2026-08-06:
- Port scanning detected (Signal Type 8)
- Ownership verification performed (Signal Type 10)
- Subnet classification analysis (Signal Type 13)
- Geolocation data collection (Signal Type 14, 6855)
No persistent malicious behavior observed. Threat observation count: 0. IP classified as not persistently malicious.
## RELATIONSHIP GRAPH
The IP maintains 12 documented relationships, all converging on:
- DNS Association: 117.166.190.35.bc.googleusercontent.com (repeated 8 times)
- Network Association: GOOGLE-CLOUD network (repeated 4 times)
Forward DNS resolution confirms googleusercontent.com domain association. Reverse DNS (PTR) resolves to the same hostname.
## THREAT INDICATORS
- Known Campaigns: None detected
- Threat Feeds: Empty
- Blacklist Count: 0 (malicious content blacklists)
- Reputation Sources: None identified
- Email Spam Source: False
## SERVICE ENUMERATION
Open Ports: None detected
HTTPS/TLS: No certificates detected
HTTP Banner: None
Server Classification: Firewalled / No Services
The target appears to be an inactive or firewalled endpoint with no exposed services.
## RECOMMENDED ACTIONS
Based on the High Risk classification:
1. Monitoring: Continue passive monitoring; no immediate blocking recommended
2. Firewall Rules: No specific iptables/nftables rules generated due to lack of active threats
3. WAF Policies: Standard Google Cloud traffic policies apply; no custom rules needed
4. Threat Hunting: Focus on the 4 DNSBL listings if false positive concerns exist
## CONCLUSION
IP 35.190.166.117 is a legitimate Google Cloud infrastructure endpoint with elevated risk scoring attributable to DNSBL listings rather than active malicious behavior. The clean neighborhood profile, absence of threat indicators, and lack of service enumeration suggest this is a standard cloud hosting resource. SOC teams should monitor for any changes in DNSBL status or service enumeration but no immediate threat response is warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.184.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 117.166.190.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 117.166.190.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | High (85%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-05 18:28:30 UTC |
| Last Seen | 2026-08-13 08:15:34 UTC |
| Profile Built | 2026-08-13 08:33:22 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 29 |
Full dossier details are available via our API.