High Risk
IP 198.235.24.177, registered to GOOGLE-CLOUD-PLATFORM under ASN AS396982 in the United States, presents a critical threat with a maximum threat-level score of 10 out of 10. This address has accumulated 195 separate abuse reports from 20 automated honeypot sensors, indicating sustained malicious activity over approximately 10 months between August 2025 and June 2026. The dominant threat profile is general hacking activity, supplemented by evidence of potential host compromise, IoT exploitation attempts, and VoIP fraud indicators. With a confidence score of 76%, analysts have high certainty this IP is actively engaged in hostile network behaviour rather than misconfiguration or benign traffic.
The detection data reveals a pattern of recurring intrusion attempts detected by multiple independent sensor systems. Suricata intrusion-detection systems flagged stream-level anomalies consistent with malware or exploit activity, while the report mix points to diverse attack vectors including unauthorized access attempts, IoT device probing, and telecommunications fraud schemes. The relatively modest activity frequency rating of 4 out of 10 suggests this is not a high-volume opportunistic scanner but rather a targeted actor methodically executing specific attack campaigns. The presence of both "Hacking" and "Exploited Host" categorisations raises the possibility that this address may itself be a compromised cloud resource repurposed as an attack platform without its operator's knowledge.
Hacking activity of this severity typically involves repeated attempts to exploit vulnerable services, inject malicious payloads, or establish persistent footholds within target networks. When combined with IoT targeting and VoIP fraud indicators, this IP poses risks across consumer, enterprise, and telecommunications environments. Organizations running exposed services, unpatched firmware on connected devices, or poorly secured VoIP infrastructure are particularly vulnerable to the techniques associated with this address. The cloud-provider registration does not imply legitimacy; threat actors routinely abuse compromised cloud instances to mask their origin and distribute attack traffic.
Site operators should block 198.235.24.177 at the network perimeter and monitor for any successful connections originating from this address. Implementing automated tools such as fail2ban or equivalent dynamic blocking solutions can proactively deny repeated intrusion attempts. Patch management, network segmentation for IoT devices, and hardening of VoIP configurations against fraudulent registration attacks are essential defensive layers. Operators of GOOGLE-CLOUD-PLATFORM infrastructure should consider reviewing this asset for potential compromise and applying acceptable-use-policy enforcement.