IPDebrief

35.190.72.41

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intellectelligence Briefing: 35.190.72.41/32

Overview

The IP address 35.190.72.41 was observed on 2026-09-13 with a Low Risk reputation score of 25. Ownership records attributed the address to Google LLC (ASN 396982) within the GOOGLE-CLOUD network (35.184.0.0/13). The address was flagged as a "Suspicious Host" due to signal incoherence (Coherence Score: 48) and contradictory profile data.

Technical Profile

Network scans identified open ports 80 (HTTP) and 443 (HTTPS). A TLS certificate issued by Sectigo Limited validated the domain `*.di.atlas.samsung.com` for the subject `di.atlas.samsung.com`. DNS hygiene was rated Excellent, with SPF and DMARC authentication enabled. The IP appeared in one DNSBL list out of eight monitored sources.

Anomaly Analysis

Multiple contradictions were recorded in the profile data. Primary geolocation sources placed the host in Kansas City, Missouri, while the TLS certificate indicated South Korea (Gyeonggi-do). Furthermore, the observed RTT (22ms) contradicted the physical distance implied by the US location (minimum expected RTT: 152.5ms). The address was associated with a BGP prefix (35.190.0.0/16) lacking valid RPKI or IRR consistency.

Recommendation

The profile indicated an unreliable security posture due to conflicting signal data. Analysts recommended applying rate-limiting rules to mitigate potential abuse associated with the contradictory profile.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
Regionβ€”
CityNew York
Timezoneβ€”
Latitudeβ€”
Longitudeβ€”

🏒 Ownership & Registration

OrganizationGoogle LLC
ASNAS396982
Network NameGOOGLE-CLOUD
CIDR Block35.184.0.0/13
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR41.72.190.35.bc.googleusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames41.72.190.35.bc.googleusercontent.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPF4/4 domains
DMARC4/4 domains
FCrDNSVerified
DNSSECNot signed
CAAPresent
Domains Checked4 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
CN=*.di.atlas.samsung.com, O="SAMSUNG ELECTRONICS CO,.LTD", S=Gyeonggi-do, C=KR
Issued by CN=Sectigo Public Server Authentication CA OV R36, O=Sectigo Limited, C=GB
Self-signed: No
SANs*.di.atlas.samsung.comdi.atlas.samsung.com
Valid From2026-03-18T00:00:00+00:00
Valid Until2026-10-02T23:59:59+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period198 days
Serial Number21B348C2A338BA9C3441C6782B0DD2BF
ThumbprintB55431E914F36F0C2B507FF3D74801152376ED2D

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
42%
26
ownership
27%
23
reputation
22%
13
geolocation
38%
25
Overall28%1021
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceContradictory (48%) β€” 3 contradiction(s)
AttributionLow (40%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement
⚠ Geo sources disagree on country: KR, US
⚠ TLS certificate claims KR but primary geo says US

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-09-05 16:23:09 UTC
Last Seen2026-09-23 02:06:35 UTC
Profile Built2026-09-23 02:16:48 UTC
Data FreshnessLive
Signal Types27
Total Observations45
πŸ” 27 signal types Β· 45 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.