# IP Intelligence Briefing: 35.254.150.167/32
Classification: Low Risk β Google Cloud Infrastructure
Date: Analysis completed on 2026-06-16
Prepared For: SOC Operations Team
---
## Executive Summary
IP address 35.254.150.167 is identified as low-risk Google Cloud infrastructure with a risk score of 25. The address belongs to the GOOGL-2 network block (35.252.0.0/14) operated by Google LLC (ASN 396982). No malicious indicators, blacklist entries, or threat campaign associations were detected during analysis.
## Technical Profile
Ownership & Registration:
- Organization: Google LLC
- Network: GOOGL-2
- ASN: 396982
- CIDR Block: 35.252.0.0/14
- RIR: ARIN
Geolocation:
- Country: United States (US)
- Region: Iowa (IA)
- City: Council Bluffs
- Geographic Consensus: True (1 source)
Network Classification:
- Infrastructure Type: Single-Service Host
- Cloud Provider: Google Cloud Platform
- Anycast: False
- Proxy/VPN/Tor: False
- CDN: False
## Services & Ports
Open Services:
- Port 22 (TCP): SSH (OpenSSH 8.9p1 Ubuntu-3ubuntu0.15)
DNS Resolution:
- PTR Hostname: 167.150.254.35.bc.googleusercontent.com
- Forward Resolution: Confirmed
- Forward Hostname: 167.150.254.35.bc.googleusercontent.com
- Domain: googleusercontent.com
## Threat Intelligence
Risk Assessment:
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Threat Indicators:
- No known campaigns detected
- No threat feed matches
- No correlated malicious IPs
## Observations & History
Signal observation history contains 19 data points collected over the analysis period. Key observations include:
- Port scanning activity detected with confidence 0.90
- SSH banner identification with confidence 0.90
- Subnet classification (35.254.150.167/24) classified as clean with confidence 0.40
- Geolocation inference for Council Bluffs, IA with confidence 0.80
- No threat persistence or persistent malicious behavior observed
Temporal analysis indicates:
- Zero ownership changes
- Zero threat observation count
- Not persistently malicious
## Network Neighborhood Analysis
Subnet: 35.254.150.167/24
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0
- Classification: Clean
- Inherited Risk: 0
Neighbor Assessment: No neighboring IPs with elevated risk scores detected in the immediate /24 subnet.
## Relationship Graph
The IP maintains consistent DNS and network relationships:
- DNS Associations: 167.150.254.35.bc.googleusercontent.com (multiple entries)
- Network Associations: GOOGL-2 (multiple entries)
Relationship consistency indicates stable infrastructure assignment.
## Control Plane Data
- Origin ASN: 396982
- BGP Prefix: 35.254.0.0/16
- DNSSEC Valid: True
- HAS CAA: True
- Route Changes (30d): 0
- MOAS: False
## Recommended Actions
No specific firewall rules or blocking recommendations were generated. The low risk score and legitimate cloud provider attribution suggest normal traffic should be permitted. No action required at this time.
---
Conclusion: IP 35.254.150.167 is classified as legitimate Google Cloud infrastructure with no malicious indicators. The address exhibits normal operational characteristics for a cloud hosting environment. No threat action is warranted based on current data.
Status: Monitor β No Action Required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 35.252.0.0/14 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 167.150.254.35.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 167.150.254.35.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 24% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-13 03:45:43 UTC |
| Last Seen | 2026-06-21 20:26:30 UTC |
| Profile Built | 2026-06-21 20:33:31 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.