Significant Threat
IP 198.235.24.105 is a high-risk address operating from Google Cloud Platform infrastructure within the United States, with a threat level of 8 out of 10 and a 77% confidence score, primarily associated with widespread hacking activity detected across 20 automated honeypot sources over approximately nine months of continuous monitoring.
Security monitoring systems recorded 220 total incident reports concerning this IP address between August 2025 and May 2026, indicating sustained hostile activity over an extended period. The dominant threat category is hacking, accounting for the overwhelming majority of recent reports, supplemented by isolated email spam activity. The detection footprint spans multiple honeypot sensors that collectively identified pattern-based intrusion attempts consistent with automated exploitation frameworks. Network routing through AS396982 (GOOGLE-CLOUD-PLATFORM) places this address within a major cloud provider's address space, which threat actors frequently abuse due to the reputation of such ranges for legitimate traffic and the challenge of distinguishing malicious from authorized cloud communications at the network perimeter.
The hacking activity linked to this IP involves automated intrusion attempts and unauthorized access vectors targeting exposed services, with Suricata-based sensors flagging anomalous SMTP protocol behavior indicating potential email abuse infrastructure. Such activity poses concrete risks to unpatched or misconfigured services, particularly those with exposed authentication mechanisms, and may serve as a precursor to credential compromise, data exfiltration, or use of the targeted host as a spam relay node. The sustained frequency of reports over many months suggests an organized scanning and exploitation campaign rather than opportunistic probing.
Site operators should immediately block or rate-limit traffic from this IP at the firewall or network edge, implement strict authentication controls on any exposed management interfaces, and enforce strong password policies alongside multi-factor authentication. Deploying intrusion detection systems and configuring automated response rules using tools such as fail2ban can proactively mitigate brute-force patterns. Regular monitoring of access logs for connections originating from this address and rapid patching of known vulnerabilities will reduce exposure to the exploitation techniques associated with this threat actor.