# IP Intelligence Briefing: 8.229.144.180/32
## Executive Summary
IP address 8.229.144.180 is a Google Cloud infrastructure host with a moderate risk score of 50. Despite the moderate classification, the IP shows no active threat indicators, no known malicious campaigns, and operates within a subnet with zero abuse density. The IP presents a legitimate Google Cloud compute service with SSH exposure.
## Ownership and Network Classification
- Organization: Google LLC (ASN 396982)
- Network: GOOGL-2, CIDR: 8.228.0.0/14
- Infrastructure Type: CloudCompute (Google Cloud Platform)
- Geolocation: United States, Oregon, The Dalles
- Registration: RIR ARIN
- Control Plane: BGP prefix 8.229.0.0/16, route stability flag: false
## Threat Assessment
Risk Score: 50 (Moderate Risk)
Threat Indicators:
- No known attacker associations
- No known spam source
- No Tor exit node activity
- Zero blacklist entries
- No known campaign affiliations
- DNSBL listed on 2 of 8 threat intelligence feeds
Network Role: Single-Service Host (CloudCompute)
## Observed Services and Ports
- Port 22/TCP: SSH service running OpenSSH 8.9p1 Ubuntu-3ubuntu0.16
- Forward DNS resolution: 180.144.229.8.bc.googleusercontent.com (googleusercontent.com)
- Email authentication: SPF and DMARC records present
## Neighborhood Analysis
- Subnet: 8.229.144.180/24
- Abuse Density: 0 (clean classification)
- Total Siblings: 1 (this IP)
- Active Siblings: 1
- Threat Siblings: 0
The /24 subnet shows no malicious activity and is classified as clean.
## Historical Observations
Analysis of 20 observations indicates:
- Recent subnet classification: clean
- No persistent malicious behavior detected
- No threat persistence indicators
- One geolocation validation anomaly noted (claimed distance 8,033 km with RTT 81ms violates minimum possible RTT of 160.65ms for that distance)
## Relationship Graph
- Primary association: GOOGL-2 network
- DNS hostname associations: 180.144.229.8.bc.googleusercontent.com
- Multiple same-network and DNS association links to Google infrastructure
## Recommended Actions
Despite the moderate risk score, the absence of actual threat indicators and clean neighborhood classification suggests this IP is legitimate Google Cloud infrastructure. However, given the risk score of 50, defensive organizations may consider:
Blocking Recommendations (if risk tolerance requires):
- iptables: `iptables -A INPUT -s 8.229.144.180 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 8.229.144.180 drop`
- nginx: `deny 8.229.144.180;`
- pfSense: `8.229.144.180/32`
- Cloudflare WAF: Block with expression `ip.src eq 8.229.144.180`
- AWS WAF: Addresses: `8.229.144.180/32`
Alternative Approach: Monitor without blocking, given:
- No active threat indicators
- Clean subnet classification
- Google Cloud infrastructure (legitimate enterprise use)
- Zero threat siblings in neighborhood
## Conclusion
This IP is Google Cloud infrastructure with a moderate risk classification but no observable malicious activity. The moderate risk score likely reflects the cloud hosting nature and generic DNSBL listings rather than confirmed malicious behavior. SOC analysts should evaluate based on organization-specific threat tolerances. The absence of threat siblings and clean subnet classification supports treating this as legitimate infrastructure unless other contextual signals indicate otherwise.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 8.228.0.0/14 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 180.144.229.8.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 180.144.229.8.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 1/4 domains |
| DMARC | 1/4 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 4 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | kuberneteskubernetes.defaultkubernetes.default.svckubernetes.default.svc.cluster.local |
| Valid From | 2026-08-11T18:27:17+00:00 |
| Valid Until | 2027-08-11T18:29:17+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 00A84CBF24D82262472FFA4803B91E66AD |
| Thumbprint | 5712CF8C05588EF7D1C2F66AEB3A3092E3DE1776 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-06 06:40:51 UTC |
| Last Seen | 2026-08-13 08:52:08 UTC |
| Profile Built | 2026-08-13 09:27:22 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 30 |
Full dossier details are available via our API.