Critical Threat
IP 104.155.11.101 is a critical-risk address with a threat level of 10/10 that has generated 257 abuse reports since March 2026, primarily linked to hacking activity detected by automated honeypot sensors. This address operates within Google LLC's network infrastructure (AS396982) located in Belgium and has been persistently engaged in intrusion attempts, exploitation probes, and web application attacks over a four-month window. The combination of a 94% confidence score and an activity frequency rating of 8/10 signals sustained, deliberate malicious behavior rather than opportunistic scanning.
The evidence base consists of 257 reports sourced from 20 distinct automated honeypot sensors, with the dominant threat category being hacking activity (19 recent reports), supplemented by exploited host indicators (2 reports) and web application attack signatures (1 report). Detection data shows attack patterns consistent with connection-based intrusion attempts, malware and exploit delivery via active connections, and targeted reconnaissance of web application surfaces using ElasticPot-style probing techniques. The reported timeframe spans from March 2026 through June 2026, indicating persistent engagement with target systems across multiple months rather than transient opportunistic activity.
The prevailing hacking activity suggests systematic attempts to exploit vulnerable services through known attack vectors and unauthorized access techniques. The exploited host classification raises the possibility that this address may be operating from a compromised platform being weaponized without the owner's knowledge, potentially amplifying its threat potential. Web application attack patterns detected indicate interest in exploitingOWASP Top 10 category vulnerabilities in exposed web services. Together, these vectors suggest a methodical threat actor pursuing multiple complementary approaches to gain unauthorized access or compromise target systems.
Network defenders should immediately block IP 104.155.11.101 at the perimeter firewall and implement rate-limiting rules on exposed services to mitigate brute-force and reconnaissance activity. Deploying or strengthening web application firewall rules will help counter probing and exploit attempts targeting web-facing applications. Organizations running exposed SSH or similar services should enforce key-based authentication, implement account lockout policies, and consider deploying defensive tools such as fail2ban to automatically block repeated connection attempts. Regular patching of internet-facing systems and continuous monitoring of authentication logs for unusual source patterns will further reduce exposure to the intrusion techniques this address has demonstrated.