IPDebrief

35.220.210.187

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 35.220.210.187/32

Classification: Moderate Risk Infrastructure Host

Date: Current Assessment

Analyst: IPDebrief Intelligence

---

## Executive Summary

IP address 35.220.210.187 is a Google Cloud infrastructure host operating within the 35.208.0.0/12 CIDR block. Risk assessment yields a score of 50 (Moderate Risk). The IP exhibits standard cloud infrastructure characteristics with SSH service exposure and minimal threat indicators. No active attack campaigns or persistent malicious behavior detected.

---

## Ownership and Network Classification

AttributeValue
**Organization**Google LLC
**ASN**396982
**Network Name**GOOGLE-CLOUD
**CIDR Block**35.208.0.0/12
**Provider**Google Cloud
**Geolocation**Hong Kong (HK)
**Registration**ARIN

The IP is classified as a Single-Service Host within Google Cloud infrastructure. Control plane analysis indicates route instability (isRouteStable: false) with an operator score of 0.3478.

---

## Threat Indicators

IndicatorStatus
**Risk Score**50/100 (Moderate)
**Abuse Confidence**Not applicable
**Known Attacker**No
**Spam Source**No
**Tor Exit Node**No
**DNSBL Listings**2 of 8 lists
**Threat Persistence**0 days
**Campaign Likelihood**None

No active threat indicators or known campaign associations identified. The IP appears to be a legitimate cloud infrastructure endpoint.

---

## Network Services and Exposure

The IP exposes SSH connectivity, consistent with standard cloud infrastructure hosting configurations. No web services or reverse proxy configurations observed.

---

## Subnet Neighborhood Assessment

Subnet: 35.220.210.187/24

Abuse Density: 0%

Classification: Clean

Active Threat Siblings: 0

Total Siblings: 1

The /24 subnet shows no malicious activity patterns or neighboring threat indicators.

---

## Historical Signal Analysis

18 observations recorded with the following patterns:

Historical data indicates stable infrastructure behavior without degradation or escalation of threat signals.

---

## Relationship Graph

All relationships indicate legitimate Google Cloud infrastructure associations with no external or suspicious entity links.

---

## Recommended Actions

Based on risk profile and observed characteristics:

1. Monitor SSH Connections: Track inbound SSH traffic to this IP for potential lateral movement or credential-based attacks

2. DNSBL Monitoring: Investigate the 2 DNSBL listings to determine if false positives or legitimate abuse indicators

3. Route Stability Alert: Monitor for potential BGP hijacking or route announcements given isRouteStable: false

4. Allow Traffic (Standard): No firewall blocking recommended; treat as legitimate Google Cloud infrastructure

Priority: LOW โ€“ Infrastructure host with moderate risk score but no active threat indicators

---

Assessment: This IP represents standard Google Cloud infrastructure with expected SSH exposure and minimal threat profile. No immediate blocking action recommended. Monitor for changes in threat indicators or route stability.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ญ๐Ÿ‡ฐ Hong Kong
RegionHK
CityHong Kong
TimezoneAsia/Hong_Kong
Latitude22.31
Longitude113.91

๐Ÿข Ownership & Registration

OrganizationGoogle LLC
ASNAS396982
Network NameGOOGLE-CLOUD
CIDR Block35.208.0.0/12
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR187.210.220.35.bc.googleusercontent.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnames187.210.220.35.bc.googleusercontent.com

๐Ÿ” DNS Hygiene

Hygiene Score100% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
17%
11
services
24%
22
ownership
35%
23
reputation
17%
12
geolocation
24%
22
Overall25%1013
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionHigh (85%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-08-05 18:28:30 UTC
Last Seen2026-08-13 08:16:02 UTC
Profile Built2026-08-13 08:39:11 UTC
Data FreshnessLive
Signal Types26
Total Observations27
๐Ÿ” 26 signal types ยท 27 observations collected
This report is generated from 26+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.