Severe Risk
IP 104.199.4.112 is a maximum-threat-level address operated by Google LLC under ASN AS396982 in Belgium, generating 248 abuse reports from automated honeypot sensors over a three-month window with a 93% confidence rating. This IP presents an severe risk profile due to sustained malicious activity dominated by hacking intrusion attempts and web application probing.
The detection data reveals this address was first reported in March 2026 and most recently in June 2026, accumulating reports across 20 distinct honeypot sensors. Of the categorized threats, hacking activity accounts for 17 confirmed incidents, web application attacks comprise 3 additional reports, and a single exploited host classification indicates this address may itself be a compromised platform being weaponized by threat actors. The activity frequency score of 4 out of 10 suggests persistent rather than burst-pattern behavior, indicating methodical ongoing scanning and exploitation attempts rather than opportunistic sweeps.
The dominant hacking activity detected includes general intrusion attempts, exploitation probes, and unauthorized access vectors targeting exposed services. These patterns represent concrete attack infrastructure being actively exercised against defensive sensors, meaning the operators behind this IP are systematically probing for vulnerabilities across target systems. The web application attack component, including ElasticPot-style probing, demonstrates specific interest in web-facing applications and their known vulnerability classes. When combined with the exploited host classification, this suggests the IP may be functioning both as an origination point for attacks and as a compromised asset participating in broader attack campaigns.
Site operators should immediately block this IP at the network perimeter and implement fail2ban or equivalent log-based blocking daemons to automate response to its probing patterns. Enforcing strong authentication on all exposed services, particularly SSH and web application endpoints, significantly reduces the effectiveness of the intrusion attempts this address is known for. Deploying a web application firewall to filter SQL injection, cross-site scripting, and file inclusion vectors addresses the web app attack category. Regular monitoring of authentication logs for source IPs matching this range and maintaining current patches across all internet-facing systems closes the exploitation pathways these attacks attempt to leverage.