Significant Threat
198.235.24.116 is a critical-risk IP address linked to sustained malicious activity, with 203 abuse reports documenting intrusion attempts and exploitation activity originating from this Google Cloud Platform address over approximately ten months.
Operating within AS396982 (GOOGLE-CLOUD-PLATFORM) in the United States, this IP has been flagged by 20 automated honeypot sensors from August 2025 through May 2026, demonstrating a consistent 4/10 activity frequency with 80% confidence in the threat assessment. The report breakdown reveals hacking activity as the dominant threat vector with 17 incidents, supplemented by 2 exploited host detections and 1 fraud VoIP report, indicating diverse attack patterns being executed from this infrastructure.
The primary hacking activity encompasses various intrusion attempts, vulnerability exploitation, and unauthorized access efforts, with honeypot sensors detecting anomalous network packets characteristic of reconnaissance and exploitation phases. The presence of exploited host indicators suggests this cloud infrastructure may itself be compromised and weaponized, functioning as an attack platform. The fraud VoIP component adds financial motivation to the threat profile, suggesting the compromised system may be leveraged for unauthorized call routing or premium-rate dialing schemes.
Site operators should implement immediate IP blocking or rate-limiting rules for 198.235.24.116 at network perimeters, strengthen authentication mechanisms on all exposed services, deploy intrusion detection systems to identify similar attack signatures, and configure automated defensive tools such as fail2ban to respond to detected intrusion patterns. Organizations utilizing Google Cloud Platform services should consider reporting this activity to the provider's abuse handling team for infrastructure-level remediation.