Notable Threat
IP 198.235.24.194 is a high-risk address operating from Google Cloud Platform infrastructure (AS396982, United States) with a threat-level score of 8/10, supported by 199 independent abuse reports and an activity frequency rating of 8/10. Automated honeypot sensors have flagged this IP across 20 distinct detection points, with the dominant activity falling under general hacking intrusion attempts, including evidence of potential exploited-host behaviour and targeted IoT/ICS exploitation activity.
The evidence base for this IP is substantial: 199 total reports have been filed over a detection window spanning August 2025 through May 2026, with a confidence score of 80 percent. Suricata intrusion-detection signatures on honeypot sensors recorded TLS invalid-record anomalies and broken acknowledgment packets — patterns frequently associated with malware or exploit delivery — alongside detection of an active SSH session on an unexpected port, indicating credential-brute-force or lateral-movement behaviour. One report classified this IP as an exploited host, suggesting the address may itself be a compromised cloud resource being weaponised by threat actors without the legitimate operator's knowledge. The remaining reports document IoT and ICS-targeted activity, consistent with scanning or exploitation attempts against poorly secured connected devices.
The dominant hacking classification encompasses multi-vector intrusion attempts including vulnerability exploitation and unauthorized-access probing. The presence of broken-ack packet signatures alongside TLS anomalies points toward either active exploit delivery or compromised-system behaviour being conducted through this address. For organisations running exposed SSH services, FTP servers, or unpatched IoT devices, this IP represents a concrete attack platform capable of automated brute-force, reconnaissance, and initial-exploitation activity. The Google Cloud infrastructure origin means blocking this address may have minimal impact on legitimate business operations while preventing known malicious traffic.
Site operators should block 198.235.24.194 at the network perimeter or firewall level and monitor logs for any associated connection attempts. Authentication hardening on any exposed services is strongly recommended — enforce key-based authentication for SSH, implement account lockout policies, and consider tools such as fail2ban to automatically ban repeat offenders. IoT and ICS devices should be network-segmented, firmware-updated, and configured with non-default credentials. If this activity persists, consider filing an abuse report with Google Cloud Platform referencing the relevant ASN to facilitate takedown of the compromised infrastructure.