# IP Intelligence Briefing: 8.229.184.160/32
Classification: Moderate Risk β Legitimate Cloud Infrastructure with Monitoring Flags
---
## Executive Summary
IP 8.229.184.160 is a Google Cloud-hosted server located in Oregon, United States. The address resolves to a legitimate Google infrastructure domain (googleusercontent.com) with valid SPF and DMARC email authentication records. Despite a moderate risk score of 50, no active threat indicators or malicious campaigns were identified. The IP is associated with a single-service host role and SSH service exposure.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **ASN** | 396982 (Google LLC) |
| **Network** | 8.228.0.0/14 (GOOGL-2) |
| **Location** | US β Oregon, The Dalles |
| **Reputation** | Moderate Risk (Score: 50) |
| **Risk Breakdown** | Provider: 0, Authority: 0 |
| **Blacklist Status** | 0 lists, 0 abuse confidence |
---
## Network Services & Exposed Ports
- SSH (TCP/22): Open with banner `SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16`
- DNS Reverse Resolution: `160.184.229.8.bc.googleusercontent.com`
- Forward DNS: Confirmed single resolution to Googleusercontent domain
- Email Authentication: SPF and DMARC records present
---
## Threat Analysis
Active Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Matches: None detected
- Threat Feeds: No correlations
Control Plane Signals
- Route stability: False
- RPKI state: Not verified
- DNSBL listings: 2 of 8 total lists
- Operator score: 0.3478 (Basic)
---
## Historical Observations
Eighteen signal observations recorded as of 2026-08-13:
- Recent subnet classification: "clean" with 0 abuse density
- Geolocation consistency: US-based with 2500km accuracy radius
- RTT validation: 82β95ms observed against 160.7ms minimum possible (8033km distance)
- No persistent malicious behavior detected (threatPersistenceDays: 0)
- Ownership stability: No changes recorded
---
## Neighborhood Analysis
Subnet 8.229.184.160/24 shows minimal threat activity:
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Abuse Density: 0
- Neighbor Risk: 8.229.184.168 (Score: 25, Authority: 90)
---
## Recommended Actions
Given the moderate risk score and Google Cloud infrastructure association, the following rules were generated:
| System | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 8.229.184.160 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 8.229.184.160 drop` |
| **nginx** | `deny 8.229.184.160;` |
| **pfSense** | `8.229.184.160/32` |
| **Cloudflare WAF** | Block expression: `ip.src eq 8.229.184.160` |
| **AWS WAF** | Block addresses: `8.229.184.160/32` |
---
## Intelligence Assessment
This IP address represents a legitimate Google Cloud service endpoint rather than malicious infrastructure. The moderate risk score appears driven by DNSBL listings and automated control plane anomalies rather than confirmed threat activity. The SSH service exposure is consistent with cloud-hosted administrative access.
Recommendation: Monitor for behavioral anomalies rather than blocking. The IP may be involved in legitimate cloud operations, and blocking could disrupt service availability. Investigate any traffic from this source only if accompanied by additional threat signals.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 8.228.0.0/14 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 160.184.229.8.bc.googleusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 160.184.229.8.bc.googleusercontent.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-12 12:22:15 UTC |
| Last Seen | 2026-08-27 10:19:51 UTC |
| Profile Built | 2026-08-29 04:34:20 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.