# IP Intelligence Briefing: 35.227.168.85/32
## Executive Summary
IP address 35.227.168.85 is a low-risk Google Cloud infrastructure endpoint with no detected malicious activity. The address belongs to Google LLC (ASN 396982) and is classified as cloud compute infrastructure located in The Dalles, Oregon, USA. No immediate threat indicators were identified.
## Risk Assessment
- Risk Score: 25/100 (Low Risk)
- Reputation: Low Risk
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
## Ownership & Infrastructure
- Organization: Google LLC
- ASN: 396982
- Network Role: Cloud Compute (Google Cloud Platform)
- Geolocation: The Dalles, Oregon, USA (45.6°N, -121.18°W)
- CIDR Block: Part of 35.227.160.0/20 BGP prefix
- Infrastructure Type: Cloud infrastructure with hosting capabilities
## Network Observations
- DNS Resolution: 85.168.227.35.bc.googleusercontent.com (Google infrastructure)
- PTR Hostnames: 85.168.227.35.bc.googleusercontent.com
- Open Ports: None detected
- Services: No active services or open ports observed
- TLS/HTTP: No TLS certificates or HTTP banner data available
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None
- Threat Feeds: No entries
## Historical Analysis
- Observation Count: 22 signals tracked
- Most Recent: 2026-06-18
- Temporal Stability: No ownership changes detected
- Threat Persistence: Not persistently malicious
- Threat Observation Count: 1
The historical record shows consistent classification as Google Cloud infrastructure with stable network characteristics.
## Neighborhood Analysis
- Subnet: 35.227.168.85/24
- Abuse Density: 0 (mostly clean classification)
- Active Siblings: 0
- Threat Siblings: 1
- Overall Classification: Clean Google Cloud neighborhood
## Relationship Graph
- Total Relationships: 36
- Primary Associations: Multiple Google Cloud network relationships
- DNS Associations: Linked to googleusercontent.com infrastructure
- Network Affiliation: Consistent GOOGLE-CLOUD network classification
## Recommended Actions
Based on the low-risk profile (25/100) and legitimate cloud infrastructure classification:
- No immediate blocking or firewall rules recommended
- Monitor for any behavioral changes if traffic patterns deviate from expected cloud traffic
- Standard logging recommended for forensic purposes
- No WAF/IPS rules required at this time
## Intelligence Conclusion
35.227.168.85 is a legitimate Google Cloud Platform infrastructure address with no malicious indicators. The IP is part of Google's US-based cloud network in Oregon. While it is listed on one DNSBL, the overall risk profile remains low, and the listing appears to be associated with general cloud infrastructure rather than malicious activity. SOC analysts should treat this as benign cloud traffic unless additional context suggests otherwise.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 85.168.227.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 85.168.227.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:16 UTC |
| Last Seen | 2026-06-27 04:58:34 UTC |
| Profile Built | 2026-06-27 23:05:19 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.