# IP INTELLIGENCE BRIEFING: 35.247.218.13
Classification: Google Cloud Compute Infrastructure
Risk Assessment: Moderate Risk (Score: 50/100)
Date: Analysis based on current intelligence
---
## EXECUTIVE SUMMARY
IP address 35.247.218.13 is a Google Cloud infrastructure endpoint (ASN 396982, GOOGLE-CLOUD network). While the IP shows no active threat indicators, geolocation validation anomalies and moderate risk scoring warrant awareness. The address is associated with cloud compute infrastructure and presents a baseline security concern due to its network role rather than active malicious activity.
---
## OWNERSHIP & INFRASTRUCTURE
- Organization: Google LLC
- ASN: 396982 (GOOGLE-CLOUD)
- CIDR Block: 35.208.0.0/12
- Network Role: Cloud Compute (Single-Service Host)
- Infrastructure Type: Cloud-hosted infrastructure
The IP resolves to Google Cloud infrastructure with DNS associations to `13.218.247.35.bc.googleusercontent.com`. Reverse DNS is confirmed and consistent.
---
## GEOLOCATION ANALYSIS
Reported Location: São Paulo, Brazil
Geographic Validation: โ ๏ธ ANOMALY DETECTED
Critical Finding: Geolocation data contains a significant validation violation:
- Claimed distance from probe source: 9,896 km
- Observed RTT: 144-151ms
- Minimum possible RTT for 9,896 km: 197.9ms
- Result: RTT violates physical distance constraints
This discrepancy suggests either misreported geolocation data or the IP is not actually serving from São Paulo. The geolocation consensus is marked as plausible=false.
---
## THREAT INDICATORS
Current Status: No active threats detected
| Indicator | Status |
|---|---|
| Blacklist Count | 0 |
| Known Attacker | False |
| Tor Exit Node | False |
| Spam Source | False |
| Abuse Confidence Score | N/A |
| DNSBL Listings | 2 of 8 lists |
| Known Campaigns | None |
| Threat Persistence | 0 days |
No correlation to active threat campaigns or malicious behavior patterns observed.
---
## NETWORK SERVICES
Active Ports:
- TCP/22 (SSH) - OpenSSH 8.9p1 Ubuntu-3ubuntu0.16
The open SSH service on a Google Cloud endpoint is consistent with legitimate cloud infrastructure but represents a potential attack surface if misconfigured.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 35.247.218.13/24
Abuse Density: 0 (Clean)
Threat Siblings: 0
Classification: Clean
The immediate /24 subnet shows no abuse indicators. The IP exists in isolation within its subnet with no adjacent threat activity.
---
## OBSERVATION HISTORY
Total Observations: 19 signals
Recent Activity: August 2026
Key temporal findings:
- Ownership changes: 0 (stable)
- Threat observation count: 0
- Persistent malicious activity: False
- One observation indicated US-based geolocation (country code mismatch with Brazil reporting)
The IP shows consistent infrastructure behavior with no evolving threat patterns over the observation window.
---
## SECURITY RECOMMENDATIONS
Action: Monitor or Block (at analyst discretion)
Given the moderate risk score (50) and geolocation inconsistencies, consider the following:
1. Firewall Rules
```bash
# iptables
iptables -A INPUT -s 35.247.218.13 -j DROP
# nftables
nft add rule inet filter input ip saddr 35.247.218.13 drop
# pfSense
35.247.218.13/32
```
2. Cloud WAF Rules
- Cloudflare WAF: Block with expression `ip.src eq 35.247.218.13`
- AWS WAF: Add to allow/block list with description "IPDebrief risk 50"
3. Assessment Context
- This is Google Cloud infrastructure (legitimate cloud provider)
- Moderate risk score may reflect baseline cloud scoring
- SSH service is typical for cloud compute instances
- Geolocation anomaly requires investigation if traffic originates from unexpected regions
---
## INTELLIGENCE CONCLUSION
35.247.218.13 is a Google Cloud infrastructure endpoint with no active malicious indicators. The moderate risk score and geolocation validation anomalies suggest this IP should be flagged for monitoring rather than blocked outright. SOC analysts should verify whether observed traffic aligns with expected Google Cloud activity patterns and whether the geolocation discrepancy impacts threat assessment.
Priority Level: LOW-MEDIUM
Recommended Action: Monitor traffic patterns; consider blocking if legitimate traffic from this IP is not expected in your environment.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGLE-CLOUD |
| CIDR Block | 35.208.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 13.218.247.35.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 13.218.247.35.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 1/4 domains |
| DMARC | 1/4 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 4 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | kuberneteskubernetes.defaultkubernetes.default.svckubernetes.default.svc.cluster.local |
| Valid From | 2026-08-12T07:37:01+00:00 |
| Valid Until | 2027-08-12T07:39:01+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 4B15369C0929A80E97767AA3D8FC3BD6 |
| Thumbprint | 178E6639C5868AD4F96FABE6D0AF96BA8E2AEE42 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-05 00:08:25 UTC |
| Last Seen | 2026-08-13 07:10:50 UTC |
| Profile Built | 2026-08-13 07:21:50 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 29 |
Full dossier details are available via our API.