INTELLIGENCE BRIEFING: IP 35.231.6.65/32
Classification: LOW RISK / INFRASTRUCTURE
Date: June 2026
Analysis Period: Historical observation data from IPDebrief
---
EXECUTIVE SUMMARY
IP address 35.231.6.65/32 is a Google Cloud infrastructure endpoint with a low-risk profile (risk score: 25). The IP is associated with Google LLC (ASN 396982) and is classified as a cloud compute resource. No active threat indicators or malicious campaign associations were identified.
---
OWNERSHIP & NETWORK CLASSIFICATION
- Organization: Google LLC
- ASN: 396982
- Network Role: Cloud Compute Infrastructure
- Provider: Google Cloud Platform
- Geolocation: Moncks Corner, South Carolina, United States (33.21°N, -80.17°W)
- Timezone: America/New_York
- Geolocation Confidence: Consensus-based, 150km accuracy radius
---
THREAT INDICATORS
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: Listed on 1 of 8 DNSBL checks
- Known Campaigns: None
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Vulnerable Services: None identified beyond standard cloud infrastructure services
---
SERVICE EXPOSURE ANALYSIS
- Open Ports: Port 22/TCP (SSH)
- SSH Banner: SSH-2.0-OpenSSH_10.0
- HTTP/HTTPS: No web services detected
- TLS Certificates: No certificate data available
- Infrastructure Type: CloudCompute (Google Cloud)
---
RELATIONSHIP GRAPH ANALYSIS
- DNS Associations: 65.6.231.35.bc.googleusercontent.com (multiple records)
- Network Affiliation: GOOGLE-CLOUD network
- Related Entities: 32 total relationships identified
- Certificate Associations: None
---
NEIGHBORHOOD ANALYSIS (Subnet 35.231.6.65/24)
- Abuse Density: 0 (Low)
- Classification: Mostly Clean
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
- Active Siblings: 0
- Threat Siblings: 1 (potential correlation)
---
OBSERVATION HISTORY
- Total Observations: 19 signal events
- Most Recent Signal: June 20, 2026
- Signal Types: SSH scanning, geolocation inference, operator scoring, cloud infrastructure classification
- Threat Persistence: 0 days (transient)
- Ownership Changes: 0
Recent observations consistently identify the IP as Google Cloud infrastructure with basic operator classification.
---
RECOMMENDED ACTIONS
Immediate Actions: None required (low-risk infrastructure)
Defensive Considerations:
- SSH service exposure is typical for cloud compute instances
- No immediate firewall blocking recommended
- Monitor for service changes or port scans
Monitoring: Standard cloud infrastructure monitoring applies. No elevated threat monitoring required.
---
INTELLIGENCE ASSESSMENT
This IP represents normal Google Cloud Platform infrastructure with expected service exposure. The low-risk profile, absence of threat indicators, and clean neighborhood metrics support classification as benign cloud infrastructure. No immediate defensive action is warranted.
Analyst Notes: The single DNSBL listing and minimal threat observation count (1) are consistent with standard cloud provider operations rather than malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 65.6.231.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 65.6.231.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.0 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 09:37:35 UTC |
| Last Seen | 2026-06-28 08:50:30 UTC |
| Profile Built | 2026-06-29 02:54:32 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.