# IP INTELLIGENCE BRIEFING
Target: 35.237.0.41/32
Classification: Google Cloud Platform Infrastructure
Risk Assessment: LOW RISK (Score: 25)
Date: Current Intelligence Cycle
---
## EXECUTIVE SUMMARY
Target IP 35.237.0.41 is confirmed as legitimate Google Cloud Platform (GCP) infrastructure. The address shows no malicious indicators, no active threat campaigns, and no evidence of abuse. Recommended posture: ALLOW with standard logging.
---
## OWNERSHIP & GEOLOCATION
- Organization: Google LLC (AS396982)
- Network Block: 35.237.0.0/16
- Location: Moncks Corner, South Carolina, US
- Infrastructure Type: CloudCompute
- Classification: Cloud Hosting Provider
The IP belongs to Google's cloud infrastructure with stable ownership and no recent registration changes observed.
---
## THREAT INDICATORS
| Indicator | Status |
|---|---|
| Known Attacker | NO |
| Tor Exit Node | NO |
| Spam Source | NO |
| Blacklist Count | 0 |
| Threat Campaigns | NONE |
| Known Campaigns | NONE |
DNSBL Status: Listed on 1 of 8 total DNSBLs (likely provider security practice, not malicious)
---
## NETWORK SERVICES & FINGERPRINTING
- Open Ports: None detected
- HTTP/HTTPS Services: None (Firewalled / No Services)
- DNS PTR: 41.0.237.35.bc.googleusercontent.com
- DNS Resolution: Confirmed forward resolution to googleusercontent.com
- TLS/SSL Certificates: None exposed
The infrastructure shows no publicly accessible services, consistent with backend cloud infrastructure.
---
## OBSERVATION HISTORY (25 Signals)
Recent Activity:
- June 2026: Consistent GCP ASN identification (396982)
- Operator scores: Basic to Minimal classification
- No threat persistence observed
- No ownership changes recorded
Temporal Analysis:
- Ownership Changes: 0
- Threat Observation Count: 1
- Persistently Malicious: FALSE
---
## RELATIONSHIP GRAPH (61 Relationships)
DNS Associations:
- All 61 relationships resolve to googleusercontent.com hostnames
- No malicious hostname associations
Network Associations:
- Same Network: GOOGLE-CLOUD
- No cross-provider relationships detected
Entity Links: No organization or certificate relationships outside Google Cloud ecosystem
---
## NEIGHBORHOOD ANALYSIS (35.237.0.0/24)
- Abuse Density: 0 (mostly_clean)
- Total Siblings: 1
- Threat Siblings: 0
- Risk Distribution: No high or medium risk neighbors
The /24 subnet shows minimal abuse activity with no neighboring threats requiring correlation.
---
## RECOMMENDED ACTIONS
Firewall/Security Posture:
- ALLOW with standard logging
- No blocking or rate-limiting required
- No specific iptables/nftables rules necessary
Monitoring Considerations:
- Log traffic for forensic baseline establishment
- Monitor for any service exposure on previously closed ports
- Track DNS queries for googleusercontent.com
---
## INTELLIGENCE SUMMARY
This IP represents standard Google Cloud Platform infrastructure with no malicious indicators. The low risk score (25), absence of threat campaigns, and clean neighborhood analysis support normal operation. The single DNSBL listing appears to be a provider security measure rather than a threat indicator. No defensive action required beyond standard logging practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 41.0.237.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 41.0.237.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 35% | 1 | 4 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 26% | 10 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-15 20:47:56 UTC |
| Last Seen | 2026-06-28 02:53:56 UTC |
| Profile Built | 2026-06-29 02:59:06 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 30 |
Full dossier details are available via our API.