🌐 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/
URL
· host
cloud.google.com
· threat 0.50 (HIGH)
· Threat Actors First seen 2026-08-06 13:13:00 · last seen 2026-08-06 14:45:34
🔄 Pivot:📁 Threat Actors
Threat score
0.50
MEDIUM
Sightings
2
1 sources
Subdomains (local)
0
from indicators
Related IPs
10
A/AAAA records
DNS records (local)
0
0 types
Reporting sources
1
0 enrichments
📡 Reporting-source breakdown
1
1 total source links on this indicator.
🏷 Tag breakdown (domain family)
No data.
📈 DNS record-type counts
No data.
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
No cached WHOIS for cloud.google.com. Resolve & cache.
📡 DNS Records
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | 172.217.75.102 |
300 |
| A | 172.217.75.138 |
300 |
| A | 172.217.75.139 |
300 |
| A | 172.217.75.100 |
300 |
| A | 172.217.75.113 |
300 |
| A | 172.217.75.101 |
300 |
| AAAA | 2607:f8b0:4023:200b::71 |
300 |
| AAAA | 2607:f8b0:4023:200b::8a |
300 |
| AAAA | 2607:f8b0:4023:200b::8b |
300 |
| AAAA | 2607:f8b0:4023:200b::66 |
300 |
| TXT | facebook-domain-verification=arpzb36y6gfzl22n4jl30bg5fsrgh0 |
600 |
| TXT | google-site-verification=FNbpLNxt8J8XYQAudCNFnig_1bP-LAUSeAePJXlfjzU |
600 |
| TXT | linkedin-site-verification=d232e0a9-aa43-41a4-8fa4-243021df793a |
600 |
| TXT | google-site-verification=6nz-JOcA8VP-mmx29RInf7-g6CTloBX9wpmWHlVSMsw |
600 |
| TXT | google-site-verification=jaH5RlwfdutdrKEaZY5nEbcReUEp9rlTOJIuMqh-SV4 |
600 |
🖥 Related IPs (10)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
🌐 Subdomains — local intel (0)
No subdomains of cloud.google.com in local intel. Check crt.sh ↗
📡 Reporting Sources (1)
MISP Galaxy Threat Actors | Threat Actors |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host