# Intelligence Briefing: 35.196.89.228
Classification: Low Risk / Infrastructure
Date: 2026-08-12
Analyst: IPDebrief Intelligence Unit
---
## Executive Summary
IP 35.196.89.228/32 is identified as Google Cloud infrastructure with a low-risk reputation score of 25. The address belongs to GOOGLE-CLOUD (ASN 396982) within the 35.192.0.0/12 CIDR block. Geolocation data indicates Moncks Corner, South Carolina, USA. No active threat indicators or malicious behavior observed.
---
## Ownership & Network Profile
- Organization: Google LLC (Google Cloud Platform)
- ASN: 396982
- Network: 35.192.0.0/12
- Classification: Cloud infrastructure, firewalled/no services exposed
- Risk Score: 25/100 (Low Risk)
- Abuse Confidence: None detected
---
## Geolocation & Infrastructure
| Field | Value |
|---|---|
| Country | United States (US) |
| Region | South Carolina (SC) |
| City | Moncks Corner |
| Coordinates | 33.21°N, -80.17°W |
| Timezone | America/New_York |
| GeoValidation | ICMP blocked - unable to validate |
The IP resolves to the hostname `228.89.196.35.bc.googleusercontent.com`, confirming it as part of Google's public infrastructure.
---
## Threat Assessment
Current Status: Clean / No Active Threats
| Indicator | Status |
|---|---|
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Blacklist Count | 0 |
| Open Ports | None detected |
| TLS/HTTP Services | None detected |
Historical Observation: 24 total observations recorded. Recent activity shows 8 blacklist listings with one high-severity listing detected on 2026-08-12. However, the overall risk profile remains low.
---
## Network Relationships
- DNS Associations: Multiple entries pointing to `228.89.196.35.bc.googleusercontent.com`
- Network Affiliations: GOOGLE-CLOUD network (35.192.0.0/12)
- Related Hosts: None identified outside of Google's infrastructure
- Campaign Correlations: None detected
---
## Neighborhood Analysis
Subnet: 35.196.89.228/24
- Abuse Density: 0 (clean)
- Threat Siblings: 0
- Active Siblings: 1
- Total Siblings: 1
The immediate /24 subnet shows no abuse activity, supporting the clean classification.
---
## Security Recommendations
Based on the IP's risk profile and infrastructure type:
1. Allow Traffic: Standard egress traffic from Google Cloud IPs is generally expected for legitimate operations.
2. Monitoring: No specific firewall rules required. Standard logging recommended.
3. Risk Mitigation: None required for this IP.
Note: No specific firewall rules were generated due to low risk classification.
---
## Conclusion
IP 35.196.89.228 is legitimate Google Cloud infrastructure with no evidence of malicious activity. The IP shows normal cloud infrastructure behavior with no threat indicators. SOC analysts may treat this IP as benign unless specific threat intelligence suggests otherwise.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.192.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 228.89.196.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 228.89.196.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-26 15:20:42 UTC |
| Last Seen | 2026-08-12 20:45:10 UTC |
| Profile Built | 2026-08-12 20:55:37 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.