# THREAT INTELLIGENCE BRIEFING
IP Address: 35.195.106.79/32
Classification: Defensive Security Assessment
Date: 2026-06-21
Analyst: IPDebrief Intelligence
---
## EXECUTIVE SUMMARY
IP address 35.195.106.79 presents as a low-risk infrastructure endpoint with no active threat indicators. The IP resolves to Google Cloud infrastructure and demonstrates stable operational characteristics with no observed malicious activity. No immediate blocking or mitigation actions recommended.
---
## TECHNICAL PROFILE
Geolocation: Belgium (BE), Brussels
ASN: 396982
BGP Prefix: 35.195.96.0/20
Routing Classification: Route unstable (false)
DNS Resolution: 79.106.195.35.bc.googleusercontent.com
Email Authentication: SPF (yes), DMARC (yes)
Open Ports: None detected
TLS/HTTP Services: None detected
---
## REPUTATION & RISK ASSESSMENT
| Metric | Value | Assessment |
|---|---|---|
| Risk Score | 0 | Minimal |
| Provider Score | 0 | Neutral |
| Authority Score | 0 | Neutral |
| Stability Score | 0 | N/A |
| Abuse Confidence Score | N/A | N/A |
| Blacklist Count | 0 | Clean |
| Known Attacker | No | False |
| Tor Exit Node | No | False |
| Spam Source | No | False |
Overall Classification: Low Risk
---
## NETWORK INFRASTRUCTURE
Infrastructure Provider: Google Cloud Platform
Connection Type: Firewalled / No Services
Cloud Classification: Infrastructure endpoint
CDN/Proxy/VPN: None detected
Mobile/Residential: False
Anycast: False
Control Plane Indicators:
- Origin ASN: 396982
- RPKI State: Not evaluated
- IRR Consistency: Not evaluated
- DNSSEC Valid: Yes
- Has CAA: Yes
Traceroute Analysis:
- Hop Count: 30
- Transit Networks: Comcast
- First Hop RTT: 0.1ms
- Last Hop RTT: 24.7ms
- Timed Out Hops: 22
---
## OBSERVATION HISTORY
Total Observations: 35
Threat Observation Count: 1
Threat Persistence Days: 0
Persistently Malicious: False
Ownership Changes: 0
Recent Signal Activity (2026-06-21):
- 13:21:01 UTC - Operator Score: 0.3478, Label: Basic
- 07:19:44 UTC - Operator Score: 0.3478, Label: Basic
- 01:18:31 UTC - Operator Score: 0.3478, Label: Basic
- 19:17:16 UTC (2026-06-20) - Operator Score: 0.3478, Label: Basic
Historical Trend: Stable operational characteristics with consistent Basic classification across multiple observations. No escalation in threat indicators observed.
---
## RELATIONSHIPS & CONNECTIVITY
Total Relationships: 22
Relationship Types: DNS Association (100%)
Associated Hostnames:
- 79.106.195.35.bc.googleusercontent.com (repeated 22x)
DNS Analysis:
- PTR Record: 79.106.195.35.bc.googleusercontent.com
- Forward Resolution: Confirmed
- Hosted Domain Count: 0
No organizational, subnet, or certificate-level relationships detected beyond DNS associations.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 35.195.106.79/24
Total Siblings: 0
Active Siblings: 0
Threat Siblings: 0
Abuse Density: 0
Inherited Risk: 0
Subnet Classification: None
Assessment: The /24 subnet shows no adjacent threat activity. No neighboring IPs flagged for abuse or malicious activity.
---
## BEHAVIORAL INDICATORS
Honeypot Hits: 0
Enumeration Strikes: 0
WAF Violations: Not evaluated
Campaign Correlation: 0 correlated IPs
Cert Matches: 0
---
## ACTIONABLE RECOMMENDATIONS
Firewall/Security Actions
- No blocking recommended β IP classified as low-risk with no active threat indicators
- Monitoring: Continue passive monitoring; IP shows stable operational characteristics
- Allow List Consideration: IP may be added to allow-list if traffic is legitimate business communication
SOC Analyst Notes
1. Google Cloud Infrastructure: IP resolves to Google Cloud services with proper email authentication
2. No Active Threats: Zero threat indicators, no blacklist presence, no known campaign associations
3. Infrastructure Endpoint: Service purpose indicates firewalled/no services β typical of cloud infrastructure
4. Stable Routing: Despite route instability flag, no malicious routing behavior observed
5. No Neighborhood Risk: Clean /24 subnet with no adjacent abuse indicators
Recommended Actions
- [ ] Monitor: Continue passive monitoring for changes in threat profile
- [ ] Allow-List: Consider adding to allow-list if traffic is verified legitimate
- [ ] No Blocking: Do not block or restrict traffic from this IP
---
BRIEFING COMPLETE
Classification: Unclassified
Distribution: SOC Team
Report Metadata & Provenance
Collection Timestamp: 2026-06-21 13:21:01 UTC (Latest Observation)
Data Collection Period: 2026-06-20 19:17:16 UTC to 2026-06-21 13:21:01 UTC
API Tier: Standard (Bulk Lookup Unavailable)
Analyst Note: Bulk lookup restricted to Pro/Enterprise tier; profile data sufficient for assessment.
End of Document.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.192.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 79.106.195.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 79.106.195.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 32% | 2 | 3 |
| reputation | 18% | 1 | 2 |
| geolocation | 24% | 2 | 2 |
| Overall | 20% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-11 03:01:22 UTC |
| Last Seen | 2026-06-26 18:12:23 UTC |
| Profile Built | 2026-06-27 11:00:10 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 47 |
Full dossier details are available via our API.