# IP Intelligence Briefing: 35.196.61.247/32
Classification: LOW RISK β Google Cloud Infrastructure
Generated: Based on IPDebrief intelligence platform data
Date: Current analysis
---
## Executive Summary
IP address 35.196.61.247 is a Google Cloud Compute infrastructure endpoint registered under Google LLC (ASN 396982). The IP demonstrates a low-risk profile with a risk score of 25/100. No active threat indicators, blacklist entries, or malicious campaign associations were identified. The address is classified as Google Cloud hosting infrastructure with firewalled/no active services exposed.
---
## Ownership and Infrastructure
| Attribute | Value |
|---|---|
| Organization | Google LLC |
| ASN | 396982 |
| RIR | ARIN |
| CIDR Block | 35.196.48.0/20 |
| Network Classification | CloudCompute / Hosting |
| Infrastructure Type | Cloud Infrastructure |
The IP originates from the Google Cloud network backbone and is part of a stable BGP route with route stability confirmed. RPKI state and DNSSEC validation are present, indicating proper cryptographic infrastructure configuration.
---
## Geolocation Data
| Field | Value |
|---|---|
| Country | United States (US) |
| Region | South Carolina (SC) |
| City | Moncks Corner |
| Coordinates | 33.21°N, -80.17°W |
| Timezone | America/New_York |
| GeoValidation | Plausible (ICMP validation blocked) |
*Note: Multiple geolocation sources report SC location, though minor discrepancies exist between Moncks Corner and North Charleston coordinates in historical observations. All sources indicate US-based deployment.*
---
## Threat Intelligence Assessment
Risk Indicators:
- Risk Score: 25 (Low Risk)
- Abuse Confidence: None detected
- Blacklist Count: 0
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
Network Classification Flags:
- Cloud Infrastructure: Yes
- CDN: No
- Proxy/VPN: No
- Mobile/Residential: No
- Bogon: No
DNS Analysis:
- PTR Hostname: 247.61.196.35.bc.googleusercontent.com
- Forward Resolution: Confirmed
- Domain: googleusercontent.com
- DNSBL Listed: 1 of 8 lists (minimal exposure)
---
## Service Exposure
Open Ports: None detected
HTTP/HTTPS: No active services exposed
TLS Certificates: None
Banner Detection: No service banners detected
The IP is configured with no active services exposed, indicating a firewalled posture typical of cloud infrastructure endpoints.
---
## Neighborhood Analysis (35.196.61.0/24)
| Metric | Value |
|---|---|
| Subnet Abuse Density | 0 (Low) |
| Classification | Mostly Clean |
| Total Siblings | 2 |
| Active Siblings | 1 |
| Threat Siblings | 2 |
| Inherited Risk | 5/100 |
Neighbor IP: 35.196.61.194 (Risk Score: 25, Authority Score: 90)
The /24 subnet maintains low abuse density with predominantly clean classification. The single active sibling IP shares similar risk characteristics.
---
## Historical Observations
Total Signal Count: 23 observations
Key Historical Signals:
- Recent geolocation data consistently reports US/SC deployment
- Control plane stability maintained with no significant route changes
- DNS and routing indicators show moderate stability
- No emergence of new threat indicators over observation period
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: No
---
## Relationship Graph
Total Relationships: 33 connections identified
Primary Associations:
- DNS Association: googleusercontent.com hostname mappings
- Network Association: GOOGLE-CLOUD infrastructure
- Multiple hostname and network-level relationships
All relationships point to legitimate Google Cloud infrastructure components.
---
## Recommended Actions
Current Risk Level: Low
Action Recommendations: None required at this time
The IP demonstrates no active malicious behavior or threat indicators. Standard cloud infrastructure handling procedures apply. No specific firewall rules or blocking recommendations are warranted based on current risk assessment.
---
## Intelligence Confidence
- Data Sufficiency: High (23 historical observations, 33 relationship links)
- Risk Assessment: Confident (Low Risk, 25/100)
- Actionability: Monitor as standard Google Cloud infrastructure
---
## Conclusion
IP 35.196.61.247/32 is identified as legitimate Google Cloud hosting infrastructure with no current threat indicators. The address operates within normal cloud compute parameters with proper routing stability and geolocation consistency. SOC teams may classify this as benign cloud infrastructure requiring no special handling beyond standard network policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | 35.196.48.0/20 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 247.61.196.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 247.61.196.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 24% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 27% | 3 | 4 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 27% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-18 15:26:43 UTC |
| Last Seen | 2026-06-28 07:37:05 UTC |
| Profile Built | 2026-06-29 01:41:32 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 29 |
Full dossier details are available via our API.