# IP Intelligence Briefing: 35.196.178.50/32
Date: 2026-07-29
Classification: Low Risk - Legitimate Cloud Infrastructure
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP address 35.196.178.50 is a Google Cloud infrastructure endpoint with a risk score of 0. The address demonstrates consistent web server behavior, operates within Google's global cloud network, and shows no malicious indicators. This IP belongs to Google LLC's GOOGLE-CLOUD network (35.192.0.0/12, ASN 396982) and is classified as a clean web server endpoint in Moncks Corner, South Carolina, US.
---
## Ownership and Network Context
| Attribute | Value |
|---|---|
| **Organization** | Google LLC |
| **Netname** | GOOGLE-CLOUD |
| **ASN** | 396982 |
| **CIDR Block** | 35.192.0.0/12 |
| **Registration** | ARIN |
| **Geolocation** | Moncks Corner, SC, US |
The IP resides within Google's global cloud infrastructure, operating as a standard web server endpoint (service purpose: Web Server).
---
## Technical Profile
Network Services:
- Port 443/TCP (HTTPS) β Active
- TLS 1.3 enabled with cipher suite: TLS_AES_128_GCM_SHA256
- HTTP/2 protocol support confirmed
- Response status code: 403 (Forbidden)
DNS Resolution:
- PTR: 50.178.196.35.bc.googleusercontent.com
- Forward resolution: Confirmed
- Email authentication: SPF and DMARC records present
SSL/TLS Certificate:
- Subject: CN=35.196.178.50
- Issuer: CN=7d11e6e5-b64d-4f8e-94a3-015cc65399c4
- SANs: kubernetes, kubernetes.default, kubernetes.default.svc
- Self-signed: No
---
## Threat Assessment
Risk Indicators:
- Risk Score: 0
- Reputation: Low Risk
- Abuse Confidence Score: N/A
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Pulsedive Risk: N/A
Campaign Correlation:
- Campaign Likelihood: N/A
- Certificate Matches: 0
- Correlated IPs: 0
No threat indicators, known campaigns, or blacklist associations were detected.
---
## Neighborhood Analysis
Subnet: 35.196.178.50/24
Abuse Density: 0 (Clean)
Classification: Clean
Total Siblings: 1
Active Siblings: 1
Threat Siblings: 0
The /24 subnet demonstrates zero abuse density with no neighboring threat indicators.
---
## Observation History
Total Observations: 19 signals recorded
Latest Activity: 2026-07-29T20:30:14 UTC
Temporal Trends:
- Ownership changes: 0
- Threat observation count: 0
- Threat persistence days: 0
- Persistently malicious: No
Recent Signal Summary:
- HTTP/2 responses with 403 status codes
- Consistent geolocation inference (Moncks Corner, SC)
- TLS certificate scans showing Kubernetes service SANs
- Stable DNS and network attributes
The historical record shows consistent, benign behavior with no escalation in risk signals.
---
## Relationship Graph
DNS Associations:
- 50.178.196.35.bc.googleusercontent.com (repeated multiple times)
Network Associations:
- GOOGLE-CLOUD (repeated multiple times)
No anomalous relationships or suspicious entity linkages detected.
---
## Security Recommendations
Risk Score: 0
Recommended Actions: None
Firewall Rules: Not required
Given the low-risk classification and legitimate cloud infrastructure context, no blocking or restrictive firewall rules are recommended. Standard logging and monitoring practices apply.
---
## Conclusion
IP 35.196.178.50 is a legitimate Google Cloud web server endpoint with no malicious indicators. The IP demonstrates normal cloud infrastructure behavior, consistent with Google's global network operations. No defensive actions are recommended beyond standard observability practices.
Threat Level: LOW
Classification: Legitimate Cloud Infrastructure
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.192.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 50.178.196.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 50.178.196.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 27% | 2 | 3 |
| services | 30% | 2 | 3 |
| ownership | 30% | 3 | 4 |
| reputation | 15% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 24% | 11 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 20:05:52 UTC |
| Last Seen | 2026-08-12 18:08:45 UTC |
| Profile Built | 2026-08-12 18:11:35 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 27 |
Full dossier details are available via our API.