# IP Intelligence Briefing: 35.225.28.181/32
Classification: LOW RISK β Cloud Infrastructure
Assessment Date: 2026-06-29
Risk Score: 25/100
## Executive Summary
IP address 35.225.28.181 is identified as Google Cloud infrastructure with a low risk profile (Score: 25). The address resolves to Google LLC (ASN 396982) within the GOOGLE-CLOUD CIDR block (35.208.0.0/12). No active threat indicators, no open services, and no blacklist listings were detected. The IP is part of a mostly clean subnet with minimal abuse density.
## Technical Profile
Ownership & Classification
- Organization: Google LLC
- ASN: 396982 (GOOGLE-CLOUD)
- Network: 35.208.0.0/12
- Infrastructure Type: CloudCompute
- Provider: Google Cloud Platform
- Country: United States (Council Bluffs, IA)
Network Characteristics
- Reputation: Low Risk
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- DNS Reputation: Clean (googleusercontent.com domain)
- PTR Record: 181.28.225.35.bc.googleusercontent.com
- Forward Resolution: Confirmed (1 hostname)
- Security Headers: SPF enabled, DMARC enabled
Service Exposure
- Open Ports: None detected
- HTTP Services: None
- TLS Certificates: None
- Status: Firewalled / No Services
## Threat Indicators
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Active Threats: None
- Campaign Associations: None
- Threat Feeds: No matches
- Malware Campaign Likelihood: Not applicable
## Behavioral History
- Observation Count: 23 signals
- Threat Persistence: 0 days
- Ownership Stability: Stable (no changes)
- Recent Activity: Consistent cloud infrastructure signals (June 2026)
- Risk Trend: Stable low risk
Historical Signals
- Cloud infrastructure classification confirmed across multiple observations
- Operator score: 0.3478 (Basic)
- DNSSEC validation: Valid
- No observed malicious behavior
## Neighborhood Analysis
- Subnet: 35.225.28.0/24
- Abuse Density: 1 (Low)
- Classification: Mostly Clean
- Active Siblings: 1
- Threat Siblings: 1 (minimal impact)
- Overall Inherited Risk: 2/100
## Related Entities
- DNS Associations: 181.28.225.35.bc.googleusercontent.com
- Network Relationships: Multiple GOOGLE-CLOUD network associations
- Control Plane: BGP prefix 35.225.16.0/20, Route stable, RPKI state available
## Recommended Actions
Firewall/Blocking
NOT RECOMMENDED FOR BLOCKING
Justification: This IP represents legitimate Google Cloud infrastructure with:
- Risk score of 25 (Low)
- No active threat indicators
- No open ports or services
- Clean reputation across all feeds
- Proper DNS and security header configurations
Monitoring Considerations
- No specific monitoring required
- Standard cloud traffic logging suffices
- No anomaly thresholds needed
## Conclusion
35.225.28.181/32 is a legitimate Google Cloud Platform IP address with no malicious indicators. The IP exhibits standard cloud infrastructure characteristics with no evidence of abuse or compromise. No defensive action is required. Standard logging and monitoring practices are sufficient.
---
*Report generated based on IPDebrief intelligence platform data. Analysis based on observed signals and historical patterns.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.208.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 181.28.225.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 181.28.225.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-29 18:15:02 UTC |
| Last Seen | 2026-06-29 06:43:33 UTC |
| Profile Built | 2026-06-29 06:48:27 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.