# INTELLIGENCE BRIEFING: 35.252.127.228/32
Classification: Low Risk β Google Cloud Infrastructure
Date: 2026-06-23
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP address 35.252.127.228 is a Google Cloud (GCP) infrastructure endpoint with a risk score of 25/100. The address is associated with Google LLC (ASN 396982) and resolved to The Dalles, Oregon. No malicious indicators, threat feeds, or abuse activity detected. Subnet classified as clean with zero abuse density.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | Google LLC |
| **ASN** | 396982 |
| **Network** | 35.252.64.0/18 |
| **Geolocation** | The Dalles, Oregon, US |
| **Infrastructure Type** | CloudCompute |
| **Service Purpose** | Firewalled / No Services |
DNS resolution confirms Google Cloud infrastructure: `228.127.252.35.bc.googleusercontent.com`.
---
## THREAT ASSESSMENT
Risk Score: 25 (Low Risk)
Blacklist Count: 0
Known Attacker: No
Tor Exit Node: No
Spam Source: No
Campaign Association: None
No threat indicators, known campaigns, or threat feed matches detected.
---
## OBSERVATION HISTORY
Total Observations: 26
Observation Period: 2026-06-23
Signal Consistency: Stable
- Geolocation: Consistently reports The Dalles, OR, US (confidence 0.80)
- Provider Classification: Confirmed Google Cloud provider (confidence 0.85)
- BGP Prefix: 35.252.64.0/18 (no route changes in 30 days)
- Threat Persistence: 0 days
- Ownership Changes: 0
No temporal escalation in risk profile observed.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 35.252.127.228/24
Abuse Density: 0
Classification: Clean
Total Siblings: 1
Active Siblings: 1
Threat Siblings: 0
No neighboring IPs flagged with abuse indicators. Subnet-wide risk distribution shows no high or medium risk addresses.
---
## RELATIONSHIP MAPPING
Total Relationships: 50
Primary Associations:
- Same Network: GOOGL-2 (multiple instances)
- DNS Association: 228.127.252.35.bc.googleusercontent.com
Relationship graph indicates standard Google Cloud network topology with no anomalous external connections.
---
## OPERATIONAL STATUS
Open Ports: None detected
TLS Certificate: None
HTTP Service: None
Banner Analysis: None
IP appears firewalled with no active services exposed.
---
## RECOMMENDATIONS
Action: Monitor only; no immediate blocking required
Rationale: This is a legitimate Google Cloud infrastructure IP with clean threat profile. However, SOC teams should:
1. Validate that traffic originates from expected Google Cloud sources
2. Monitor for behavioral anomalies that don't align with GCP patterns
3. Apply standard cloud provider firewall rules as appropriate for organizational policy
No firewall rules recommended based on current risk assessment.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 228.127.252.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 228.127.252.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 26% | 2 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:17 UTC |
| Last Seen | 2026-06-27 05:03:06 UTC |
| Profile Built | 2026-06-27 23:08:47 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.