IP-Adresse

35.216.172.131

IPv4 Öffentlich
CH CH
AS15169
GOOGLE
193 Reports
Diese IP-Adresse steht unter Beobachtung Verdächtige Aktivität festgestellt – bitte genau beobachten
10/10 Bedrohung
68% Selbstvertrauen
193 Reports

Analyse von Threat Intelligence

KI-gestützte Sicherheitsbewertung auf der Grundlage aggregierter Bedrohungsdaten

Top 10% High Threat
CH
CH Standort
GOOGLE ASN 15169
193 Reports
Honeypot Datenquelle

Maximum Danger

IP 35.216.172.131 is a maximum-threat-level address operated within Google Cloud infrastructure (AS15169) that has accumulated 189 independent abuse reports across automated honeypot sensors between October 2025 and May 2026, indicating sustained malicious activity originating from what appears to be a cloud-hosted environment in Switzerland. Despite a relatively low activity frequency score of 2 out of 10, the IP carries a 10 out of 10 threat level, suggesting that each detected engagement poses severe risk to targeted systems.

The detection data reveals 189 total reports sourced from 20 distinct honeypot sensors, with the dominant threat categories being Hacking (17 reports), Exploited Host (10 reports) and Web App Attack (3 reports). Network inspection captured multiple Suricata signatures including indicators of SMBv1 protocol usage associated with malware and exploit delivery, HTTP unexpected request body anomalies pointing to exploitation tooling, and TLS invalid record type signatures consistent with encrypted command-and-control communications. The combination of these patterns across a major cloud provider's IP space suggests the address is likely functioning as an attack platform, either through compromise of a cloud-hosted asset or deliberate abuse of the provider's infrastructure for threat operations.

The reported Exploited Host classification indicates this IP may belong to a legitimate system that has been compromised and weaponised without the owner's knowledge, a common occurrence in cloud environments where misconfigurations or unpatched services become entry points for attackers. The Web App Attack signatures suggest active probing for OWASP Top 10 vulnerabilities, while the SMBv1 and malware-related Suricata alerts align with lateral movement and remote-code-execution techniques frequently observed in ransomware and espionage operations. The TLS anomalies particularly indicate sophisticated threat actors employing encrypted channels to evade detection.

Site operators with exposed services should immediately block this IP at the network perimeter and implement fail2ban or similar dynamic firewall rules to auto-blacklist repeat offenders. All exposed web applications should be audited against OWASP Top 10 vulnerabilities, with particular attention to file-inclusion and injection vectors. Systems should be reviewed for unnecessary SMBv1 usage and legacy TLS configurations. Organizations operating Google Cloud infrastructure should consider reporting this IP to Google's Trust and Safety team for abuse investigation, and ensure cloud-hosted assets follow hardening guidelines including least-privilege IAM policies and regular vulnerability scanning.

Bedrohlicher als „93“ % der überwachten IP-Adressen

Threat Categories

Hacking 21
Exploited Host 18
Web App Attack 4

Technische Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Empfohlene Abhilfemaßnahmen

Keep systems patched, implement intrusion detection, and follow security best practices.

Cloud Infrastructure

This IP operates from Google Cloud Platform cloud infrastructure. Cloud-hosted threats can be provisioned and abandoned quickly, affecting attribution.

Cloud-hosted malicious activity often indicates automated or scalable attack infrastructure.

Sicherheitsempfehlungen

Continue monitoring for emerging patterns.

Diese Analyse wird automatisch aus aggregierten, anonymisierten Threat Intelligence-Daten generiert. Es werden keine personenbezogenen Daten angezeigt oder gespeichert. Die Genauigkeit der Auswertung hängt vom Umfang und der Vielfalt der verfügbaren Daten ab.

Reputation Summary

Gefahrenstufe 10/10 Critical
Critical
Häufigkeit der Aktivitäten 5/10 Moderate
Confidence Score 60% High Confidence

Confidence History

26. Okt. 2025 - 26. Juni 2026
68% Aktuell
Stable Trend

Der Confidence Score gibt die Zuverlässigkeit der Bedrohungsbewertung auf der Grundlage der Anzahl und der Qualität der Reports an.

Sicherheitsreports (30)

Datum Kategorien Quelle Selbstvertrauen
Hacking Exploited Host Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Honeypot 75%
Hacking Web App Attack Honeypot x2 75%
Hacking Honeypot 75%
Hacking Exploited Host Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Honeypot 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Honeypot 75%
Hacking Web App Attack Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Hacking Honeypot 75%
Hacking Exploited Host Honeypot x2 75%
Exploited Host Honeypot 75%
Web App Attack Honeypot 75%
Web App Attack Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%

Technische Details

Grundlegende Informationen

IP-Adresse
35.216.172.131
IP-Version
IPv4
Netzwerktyp
Öffentlich
Tor-Netzwerk
Nein
Netzwerkklasse
Class A

Geolokalisierung

Land
CH CH
ASN
AS15169
ISP
GOOGLE

DNS-Informationen

Reverse DNS
131.172.216.35.bc.googleusercontent.com
PTR-Eintrag
Ja
Verbindungstyp
Dynamisch

Statistiken

Gesamtzahl der Reports
193
Erstmals gemeldet
25 Okt. 2025
Zuletzt gemeldet
26 Juni 2026, 22:15

Netzwerk-Reputation

Analyse des gesamten Netzwerks (ASN), zu dem diese IP-Adresse gehört, um Informationen zum Hosting-Anbieter und zu netzwerkweiten Bedrohungsmustern zu liefern.

Netzwerkidentität

AS15169
Google LLC
CH CH

Bewertung von Netzwerkbedrohungen

2/10
Dieses Netzwerk scheint relativ sicher zu sein und weist nur sehr wenige Anzeichen für Sicherheitsrisiken auf.

Netzwerkstatistiken

34
Gesamtzahl der überwachten IP-Adressen
784
Gesamtzahl der Reports
23.1
Reports pro IP-Adresse

Netzwerkkontext

Diese IP-Adresse gehört zu Google LLC (AS 15169), das in unserem Überwachungssystem 34 IP-Adressen verwaltet. Von diesen wurden 784 wegen verdächtiger Aktivitäten gemeldet, was zu einer netzwerkweiten Gefahrenstufe von 2 /10 geführt hat.

Netzwerkstatus: Dieses Netzwerk scheint gut gewartet zu sein und weist nur geringe Sicherheitsrisiken auf.

Vergleichende Analyse

Wie sich diese IP-Adresse im Vergleich zu anderen in unserer Threat Intelligence-Datenbank darstellt

93 %

Globales Bedrohungsranking

Diese IP-Adresse stellt von allen IP-Adressen in unserer Datenbank die größte Bedrohung dar: 93 %.

Die gefährlichsten 10 %

Globaler Vergleich

Im Vergleich zu den weltweit gemeldeten IP-Adressen auf 312.384

Gefahrenstufe 10/10 avg: 6,0 ++
Gesamtzahl der Reports 193 avg: 18 ++

Netzwerkvergleich

Im Vergleich zu den IP-Adressen unter 57 im ASN 15169

Gefahrenstufe 10/10 Netzwerk-Durchschnitt: 6,4 ++
Gesamtzahl der Reports 193 Netzwerk-Durchschnitt: 15 ++
Der Netzwerk-GOOGLE hat eine Gesamtbedrohungsstufe von 2 /10

Geografischer Vergleich

Im Vergleich zu den IP-Adressen unter 696 in CH

Gefahrenstufe 10/10 Landesdurchschnitt: 6,2 ++
Gesamtzahl der Reports 193 Landesdurchschnitt: 31 ++
Kennzahlen:
++ Deutlich höher + Höher = Ähnlich - Nach unten -- Deutlich niedriger

Geografische Verteilung der Bedrohungen

292.711 Weltweit erfasste Sicherheitsvorfälle • In den letzten 24 Stunden: 17.660 Protokolle

FEED

Die größten Bedrohungsquellen

  1. 01
    US
    United States US
    65.787 22.5%
  2. 02
    IN
    India IN
    49.120 16.8%
  3. 03
    CN
    China CN
    35.633 12.2%
  4. 04
    BR
    Brazil BR
    15.556 5.3%
  5. 05
    DE
    Germany DE
    10.500 3.6%
  6. 06
    PK
    Pakistan PK
    8.479 2.9%
  7. 07
    ID
    Indonesia ID
    8.404 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.394 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 weitere Länder

GEFAHRENSTUFE
NIEDRIG MED HOCH

Geografische Daten werden aggregiert und anonymisiert. Es werden keine personenbezogenen Daten angezeigt.

Karte: simplemaps.com (MIT License)

Verwandte IPs

Weitere IP-Adressen, die aufgrund von Netzwerk- oder Verhaltensähnlichkeiten mit dieser Adresse in Verbindung stehen

IP-Adressen desselben Netzbetreibers aus demselben autonomen System (AS).

20 Verwandte IPs
8.6/10 Durchschnittliche Bedrohung
72% Durchschnittliche Konfidenz
18 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

IP-Adressen aus demselben Land mit ähnlichen Bedrohungsprofilen.

15 Verwandte IPs
9.2/10 Durchschnittliche Bedrohung
97% Durchschnittliche Konfidenz
15 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

Export- und Firewall Rules

Laden Sie Bedrohungsdaten herunter oder erstellen Sie Firewall Rules, um diese IP-Adresse zu blockieren

JSON-Bericht

Strukturiertes Datenformat für die Integration mit Sicherheitstools und SIEM-Systemen.

{
    "ip_address": "35.216.172.131",
    "threat_level": 10,
    "confidence_score": 68,
    "total_reports": 193,
    "country_code": "CH",
    "isp_name": "GOOGLE",
    "asn": "15169",
    "first_reported": "2025-10-25 13:56:31",
    "last_reported": "2026-06-26 22:15:46",
    "exported_at": "2026-08-06T18:53:21+02:00",
    "source": "https://reportedip.com/ip/35.216.172.131/"
}

GDPR Compliant: Die Exporte enthalten ausschließlich IP-bezogene Bedrohungsdaten. Es sind weder personenbezogene Daten noch Angaben zum Melder enthalten.