INTELLIGENCE BRIEFING: 35.190.176.164
Classification: Moderate Risk | Status: Active Infrastructure | Date: 2026-08-05
---
IP IDENTIFICATION
Target: 35.190.176.164/32
Organization: Google LLC (GOOGLE-CLOUD)
ASN: 396982
Location: North Charleston, South Carolina, US
Geolocation Confidence: Validated via multiple sources
RISK ASSESSMENT
Overall Risk Score: 50 (Moderate)
Abuse Confidence: Low
DNSBL Listings: 2 of 8 major lists
Threat Indicators: None detected
Campaign Correlation: None
The IP maintains a moderate risk posture attributable to its cloud provider status rather than malicious activity. Risk profile is stable with zero ownership changes and no persistent threat indicators observed.
NETWORK CONTEXT
Infrastructure Type: Google Cloud Platform (GCP)
Network Role: Firewalled / No Services Active
Open Ports: None detected
TLS/HTTP Services: Inactive
DNS Resolution: 164.176.190.35.bc.googleusercontent.com
Reverse DNS: Valid and consistent
Forward Confirmation: Confirmed
THREAT INTELLIGENCE
- Threat Feeds: No matches across monitored threat intelligence sources
- Known Campaigns: No associations with active malware campaigns or botnets
- Attacker Reputation: Not flagged as known attacker, spam source, or Tor exit node
- Scanning Activity: No active scanning or reconnaissance signals observed
HISTORICAL ANALYSIS
Observation Count: 21 signals tracked
Time Span: Recent monitoring window (last 30 days)
Threat Persistence: None detected
Ownership Changes: 0
Stability Label: Consistent infrastructure
Control plane analysis indicates route stability with no significant BGP anomalies. DNSSEC validation confirmed.
NEIGHBORHOOD ANALYSIS
Subnet: 35.190.176.0/24
Abuse Density: 0 (Clean)
Threat Siblings: 0
Classification: Clean
No adjacent IPs in the /24 subnet show malicious indicators. The infrastructure block demonstrates normal Google Cloud operational patterns.
RECOMMENDED ACTIONS
Based on the moderate risk classification and cloud provider context, the following actions are recommended:
1. Traffic Allowance: Permitted with standard logging. The IP represents legitimate Google Cloud infrastructure with no active threat indicators.
2. Rate Limiting: Apply standard rate limiting rules for Google Cloud IPs to prevent abuse of cloud resources.
3. DNSBL Monitoring: Monitor for changes in DNSBL status. Current listing count (2/8) warrants periodic review.
4. Signature Rules: Consider adding to allowlist for Google Cloud infrastructure if not already configured.
SOC DECISION MATRIX
| Condition | Action |
|---|---|
| Inbound Connection | Allow with logging |
| Outbound Connection | Allow (no restrictions) |
| Port 22/23/25 | Monitor (cloud provider services) |
| Port 80/443 | Allow (expected web traffic) |
| Port 22 (SSH) | Rate limit to 10/min |
CONCLUSION
35.190.176.164 is a legitimate Google Cloud Platform infrastructure IP with moderate risk due to provider classification rather than malicious activity. No active threats detected. Standard Google Cloud infrastructure handling is appropriate. The subnet shows clean abuse metrics with no threat siblings. Routine monitoring recommended.
---
Report Generated: 2026-08-05
Data Sources: IPDebrief Intelligence Platform
Classification: Defensive Security Intelligence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.184.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 164.176.190.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 164.176.190.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 28% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 16:42:04 UTC |
| Last Seen | 2026-08-12 23:53:24 UTC |
| Profile Built | 2026-08-13 00:01:53 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.