# IP Intelligence Briefing: 35.237.98.160
## Executive Summary
IP 35.237.98.160 is a Google Cloud infrastructure address associated with googleusercontent.com. Risk score rated at 40 (Moderate Risk) with no confirmed malicious indicators. The IP presents standard cloud compute characteristics but shows geolocation inconsistencies requiring verification.
## Ownership & Classification
| Attribute | Value |
|---|---|
| Organization | Google LLC |
| ASN | AS396982 (GOOGLE-CLOUD) |
| CIDR Block | 35.208.0.0/12 |
| Network Role | CloudCompute / Hosting |
| Infrastructure Type | Cloud infrastructure |
## Risk Assessment
- Overall Risk Score: 40 (Moderate)
- Abuse Confidence: Not elevated
- Blacklist Status: Clean (0 blacklists)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
## Threat Indicators
No active threat indicators detected. The IP has no known campaign associations and shows no evidence of persistent malicious activity. Historical observation count of 25 signals indicates normal operational activity within cloud infrastructure bounds.
## Network Behavior
- Open Ports: None detected
- Services: No active services exposed (firewalled)
- DNS Resolution: Forward confirmed to `160.98.237.35.bc.googleusercontent.com`
- Email Authentication: SPF and DMARC records present
## Geolocation Analysis
- Claimed Location: Moncks Corner, SC, US
- Validation Status: β οΈ Geo validation anomalies detected
- Issue: RTT measurement of 51ms contradicts claimed distance of 6,958km (minimum expected RTT: 139.2ms)
- Implication: Geolocation data may be inaccurate or spoofed; standard for cloud IP reporting
## Neighborhood Analysis
Subnet 35.237.98.0/24 shows clean classification with 0 abuse density. No elevated-risk sibling IPs observed within the /24 range.
## Recommended Actions
Based on current risk profile, no immediate blocking recommended. However, firewall rules may be applied per organizational policy:
```bash
# iptables
iptables -A INPUT -s 35.237.98.160 -j DROP
# nftables
nft add rule inet filter input ip saddr 35.237.98.160 drop
```
Note: These rules are probabilistic and should be combined with other signals before enforcement.
## Analyst Notes
The IP resolves to Google Cloud infrastructure with standard DNS PTR records. While the risk score is moderate (40), no active malicious behavior has been identified. The geolocation inconsistency is a common characteristic of cloud provider IP reporting and does not necessarily indicate compromise. Recommend monitoring for behavioral anomalies rather than static blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.208.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 160.98.237.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 160.98.237.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 10 | 14 |
| Data Coherence | Mixed Signals (65%) β 2 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β High authority score (90) but appears on threat lists (risk 40)
π Observation Timeline π Live
| First Seen | 2026-07-21 19:03:28 UTC |
| Last Seen | 2026-08-12 16:26:21 UTC |
| Profile Built | 2026-08-12 16:54:25 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 33 |
Full dossier details are available via our API.