High Risk
IP 198.235.24.195 is a critical-risk address operating from Google Cloud Platform infrastructure in the United States (AS396982), generating 175 abuse reports across automated honeypot sensors since August 2025 with a threat level rating of 10 out of 10. The dominant threat profile centers on general hacking activity including unauthorized SSH session establishment and SMB protocol exploitation attempts, alongside isolated web application probing and evidence the host may itself be compromised. With 20 distinct detection sources reporting and a confidence score of 82 percent, the malicious reputation of this address is well-established and ongoing.
Detection sensors identified this IP through multipleSuricata signatures, including alerts for active SSH sessions on non-standard ports, application-layer protocol mismatches, and malformed SMB request dialects consistent with exploitation tooling. Additional monitoring captured generic attack connections and web application reconnaissance activity via ElasticPot-style probes with broken stream acknowledgements. The 175 reports spanning August 2025 through May 2026 indicate persistent, sustained engagement rather than opportunistic scanning, while the exploited-host classification signals this address may function both as an attack platform and as a compromised asset under external control.
The hacking activity detected against this IP reflects systematic intrusion preparation: SSH sessions on unexpected ports suggest credential stuffing or brute-force operations attempting to establish persistent access, while SMB malformed requests indicate exploitation attempts against Windows file-sharing services. For network operators running exposed SSH daemons or SMB servers, such traffic represents a direct pathway to unauthorized system access, lateral movement, and potential ransomware deployment. The web application probing component further suggests reconnaissance targeting web-facing services for subsequent vulnerability exploitation.
Organizations should immediately block 198.235.24.195 at the network perimeter firewall and implement geo-based restrictions limiting access to AS396982 address space unless business requirements demand otherwise. Enforcing key-based SSH authentication exclusively, disabling root login, and deploying fail2ban or equivalent tools to throttle repeated authentication attempts will substantially reduce the effectiveness of any continued brute-force efforts. Regular audit of exposed services, timely patching, and deployment of intrusion detection systems capable of flagging Suricata-style protocol anomalies will help security teams detect and neutralize similar threats. If this IP has established any sessions within your environment, forensic investigation for indicators of compromise is strongly advised.