IPDebrief

35.221.5.154

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP Intelligence Briefing: 35.221.5.154

Subject: Google Cloud Infrastructure IP Analysis

Date: 2026-08-13

Risk Classification: Moderate Risk (Score: 40/100)

Infrastructure Provider: Google Cloud Platform (GOOGLE-CLOUD)

---

Ownership and Network Classification

The target IP 35.221.5.154 is registered to Google LLC, operating within the GOOGLE-CLOUD network infrastructure (ASN: 396982). The IP resides in the 35.208.0.0/12 CIDR block, classified as cloud compute infrastructure with hosting capabilities. The IP resolves to the googleusercontent.com domain via reverse DNS (154.5.221.35.bc.googleusercontent.com).

Geolocation and Technical Findings

Geolocation data indicates Ashburn, VA, US (39.04, -77.49), though validation flags show discrepancies: Round-trip time measurements (25-42ms) contradict the claimed geographic distance of 6,296km, suggesting potential proxying or measurement anomalies. The IP is not classified as Tor, proxy, or residential infrastructure.

Network Services and Scanning Activity

Active service scanning identified SSH on port 22 (OpenSSH 8.9p1 Ubuntu-3ubuntu0.16). The IP shows no TLS certificate or HTTP service exposure. Control plane analysis indicates the IP is not route-stable and is not listed as a MOAS (Multiple Origin Autonomous System) resource.

Threat Intelligence Indicators

The IP appears on 2 DNSBL listings out of 8 lists scanned, with maximum severity rated as high. Abuse confidence score data unavailable. No known attacker attribution, campaign associations, or threat feed matches. Historical analysis reveals 19 observations over the monitored period.

Neighborhood Analysis

The /24 subnet (35.221.5.0/24) demonstrates low abuse density with zero high-risk neighbors. One sibling IP (35.221.5.170) registers a risk score of 25 with authority score of 90. Overall subnet threat indicators remain benign.

Relationship Graph

The IP maintains associations with:

Historical Trend Analysis

Observation history indicates recent activity dated 2026-08-13. Multiple signals captured include:

No persistent malicious behavior observed over the monitoring window.

Recommended Actions

Based on the moderate risk profile and cloud infrastructure classification:

1. Monitor DNSBL listing status for potential abuse correlation

2. Verify SSH access requirements if this IP is whitelisted

3. Continue observation of geolocation validation discrepancies

4. No immediate firewall action required; IP remains within expected cloud provider parameters

---

Analyst Notes: This IP represents legitimate Google Cloud infrastructure with minor threat indicator listings. The moderate risk score (40) primarily reflects DNSBL associations rather than confirmed malicious activity. SOC teams may monitor for correlation with other flagged IPs from the same cloud infrastructure block.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVA
CityAshburn
TimezoneAmerica/New_York
Latitude39.04
Longitude-77.49

🏒 Ownership & Registration

OrganizationGoogle LLC
ASNAS396982
Network NameGOOGLE-CLOUD
CIDR Block35.208.0.0/12
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR154.5.221.35.bc.googleusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames154.5.221.35.bc.googleusercontent.com

πŸ” DNS Hygiene

Hygiene Score100% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
0%
00
routing
0%
00
services
0%
00
ownership
50%
23
reputation
0%
00
geolocation
25%
11
Overall12%34
Coverage: 2/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-08-10 23:37:07 UTC
Last Seen2026-08-27 22:06:34 UTC
Profile Built2026-08-29 03:39:55 UTC
Data FreshnessLive
Signal Types22
Total Observations25
πŸ” 22 signal types Β· 25 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.