# IP INTELLIGENCE BRIEFING: 35.203.211.78/32
Date: 2026-06-19
Classification: Cloud Infrastructure (Google Cloud Platform)
Risk Level: Low (Score: 25/100)
---
## EXECUTIVE SUMMARY
IP 35.203.211.78 is a low-risk Google Cloud Compute infrastructure endpoint hosted in London, United Kingdom. The IP demonstrates stable cloud-hosting characteristics with no active threat indicators, no open services, and a reputation profile consistent with legitimate cloud infrastructure. The /24 subnet exhibits mixed abuse density with 20 of 44 sibling IPs flagged as threats.
---
## OWNERSHIP & INFRASTRUCTURE
- Organization: Google LLC (ASN: 396982)
- Infrastructure Type: CloudCompute / Hosting
- Network Role: Cloud Provider
- CIDR Block: 35.203.211.0/24
- Geolocation: London, England, GB (51.51°N, 0.13°W)
- Timezone: Europe/London
---
## REPUTATION & THREAT PROFILE
- Risk Score: 25/100 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Threat Indicators: None detected
- Blacklist Count: 0
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Campaign Associations: None
---
## NETWORK SERVICES & DNS
- Open Ports: None detected
- PTR Hostname: 78.211.203.35.bc.googleusercontent.com
- Forward Resolution: googleusercontent.com
- DNSSEC: Valid
- Email Authentication: SPF and DMARC configured
- HTTP Services: Not responding (Firewalled / No Services)
---
## SUBNET ANALYSIS (35.203.211.0/24)
- Abuse Density: 0.4545 (Mixed classification)
- Total Sibling IPs: 44
- Active Siblings: 23
- Threat Siblings: 20
- Risk Distribution: High: 0 | Medium: 29 | Low: 14
- Inherited Risk Score: 18
Key neighbor observations include multiple IPs with risk scores of 25-50, predominantly associated with Google Cloud infrastructure with authority scores of 90, indicating legitimate but potentially abused cloud resources.
---
## OBSERVATION HISTORY
- Total Observations: 23
- Recent Activity: Signals observed as recent as 2026-06-19
- Geolocation Consensus: Confirmed (London, GB)
- Operator Score: 0.3478 (Basic)
- Route Stability: Unstable
- DNSBL Listing: 1 of 8 lists
- Threat Persistence: None (0 days)
- Ownership Changes: 0
Historical signals show consistent geolocation assignment and operator scoring with no escalation in threat profile over the observation period.
---
## RELATIONSHIP GRAPH
- Primary Associations: Google Cloud network infrastructure
- DNS Associations: googleusercontent.com hosted domains
- Network Links: Multiple GOOGLE-CLOUD network references
- Certificate Subjects: None detected
---
## SECURITY ACTIONS & RECOMMENDATIONS
Based on the IP's low-risk profile and cloud infrastructure classification:
- Firewall Policy: Standard cloud security rules apply; no specific block/restrict required
- Monitoring: No enhanced monitoring recommended
- Threat Mitigation: Not applicable
The IP represents legitimate cloud infrastructure with no evidence of malicious activity. Standard cloud provider security controls are sufficient.
---
## ANALYST NOTES
This IP should be treated as low-priority infrastructure. The presence of 20 threat siblings in the subnet does not elevate this specific endpoint's risk profile, as the threat indicators are isolated to other addresses. The subnet's mixed classification reflects typical Google Cloud usage patterns where legitimate services coexist with potentially compromised resources.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 78.211.203.35.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 78.211.203.35.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 17:18:01 UTC |
| Last Seen | 2026-06-27 13:52:12 UTC |
| Profile Built | 2026-06-28 07:56:42 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.