# IP INTELLIGENCE BRIEFING: 35.205.96.69/32
Classification: Google Cloud Compute Infrastructure
Risk Assessment: Low Risk (Score: 15)
Report Date: Current
Data Sources: IPDebrief Intelligence Platform
---
## EXECUTIVE SUMMARY
IP 35.205.96.69/32 is a legitimate Google Cloud infrastructure address classified as low-risk. The IP operates within Google's cloud computing network (ASN 396982) with no active threat indicators or malicious campaign associations. BGP routing is stable with valid RPKI attestation.
---
## NETWORK ATTRIBUTION
| Attribute | Value |
|---|---|
| **Organization** | Google LLC |
| **ASN** | 396982 |
| **Infrastructure Type** | CloudCompute (Google Cloud) |
| **Geolocation** | Belgium, St. Ghislain (50.45°N, 3.82°E) |
| **Country Code** | BE |
| **RIR Registry** | ARIN |
| **BGP Prefix** | 35.205.96.0/20 |
| **RPKI State** | Valid |
| **Route Stability** | Stable (0 route changes in 30d) |
---
## THREAT INTELLIGENCE
Risk Indicators:
- Risk Score: 15 (Low Risk)
- Abuse Confidence Score: Not applicable (cloud infrastructure)
- Threat Feeds: None detected
- Blacklist Status: Listed on 1 of 8 DNSBL lists (likely cloud infrastructure filtering)
- Tor/Proxy/VPN: Not detected
- Campaign Associations: None
- Known Attacker: No
Services:
- No open ports detected
- No TLS certificates
- No active services exposed
- Firewall/no services configuration
Network Classification:
- Cloud hosting infrastructure
- Firewalled endpoint
- Not residential, mobile, or proxy
---
## OBSERVATION HISTORY
Historical Activity (36 observations):
- Recent observations (June 2026) confirm stable cloud infrastructure classification
- Operator score consistently rated "Professional" (0.8696)
- Geographic signals consistently resolve to Belgium (St. Ghislain)
- No evidence of persistent malicious activity
- Ownership changes: None detected
- Threat persistence: 0 days (not persistently malicious)
Signal Evolution:
- Routing signals: Professional classification maintained
- Infrastructure signals: CloudCompute confirmed across multiple observations
- Geographic inference: Consistent multi-signal inference to Belgium
- No degradation in signal quality or reputation
---
## RELATIONSHIP ANALYSIS
Connected Entities: 268 relationships identified
Primary Associations:
- Network: GOOGLE-CLOUD (multiple associations)
- DNS Hostnames: 69.96.205.35.bc.googleusercontent.com
- DNS Type: Forward resolution confirmed
Relationship Categories:
- Same Network: Multiple GOOGLE-CLOUD network associations
- DNS Association: Reverse DNS to googleusercontent.com domain
- No associations to known malicious infrastructure
---
## NEIGHBORHOOD ANALYSIS
Subnet: 35.205.96.69/24
| Metric | Value |
|---|---|
| **Abuse Density** | 1 (Very Low) |
| **Classification** | Mostly Clean |
| **Active Siblings** | 1 |
| **Threat Siblings** | 1 |
| **High Risk Neighbors** | 0 |
| **Medium Risk Neighbors** | 0 |
Assessment: Neighborhood exhibits minimal abuse activity consistent with cloud infrastructure deployment.
---
## RECOMMENDED ACTIONS
Security Operations:
1. Allow Traffic: This IP is legitimate Google Cloud infrastructure. No blocking required for standard operations.
2. Monitor DNSBL: Investigate the single DNSBL listing if it impacts service availability.
3. Rate Limiting: Apply standard cloud infrastructure rate limiting if applicable to your services.
Firewall Rules:
- No firewall rules required for blocking
- Optional: Whitelist for Google Cloud access if needed for business operations
- Monitor for any unusual traffic patterns from this IP
Threat Hunting:
- No threat indicators detected
- No campaign correlations
- No malicious behavior observed in history
---
## CONCLUSION
IP 35.205.96.69/32 represents legitimate Google Cloud compute infrastructure with a low-risk profile. The IP demonstrates professional routing characteristics, stable BGP attributes, and no malicious indicators. No defensive actions are required beyond standard operational monitoring. The single DNSBL listing is consistent with cloud infrastructure filtering and should not be treated as a security concern.
Threat Level: LOW
Recommendation: NO ACTION REQUIRED
Priority: Routine Monitoring
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | โ |
| CIDR Block | 35.205.96.0/20 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 69.96.205.35.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 69.96.205.35.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 27% | 4 | 5 |
| services | 20% | 2 | 3 |
| ownership | 24% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 26% | 14 | 22 |
| Data Coherence | Consistent (100%) |
| Attribution | High (100%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:16 UTC |
| Last Seen | 2026-06-27 04:56:14 UTC |
| Profile Built | 2026-06-27 23:02:58 UTC |
| Data Freshness | Live |
| Signal Types | 32 |
| Total Observations | 38 |
Full dossier details are available via our API.