Notable Threat
IP 198.235.24.211, registered to Google Cloud Platform under ASN AS396982 in the United States, is a critical-risk address with a threat level of 10/10, backed by 225 independent abuse reports submitted through 20 automated honeypot sensors between November 2025 and May 2026. This IP demonstrates sustained malicious activity with a frequency rating of 6/10 and a 78% confidence score, indicating a highly reliable assessment of its hostile behaviour.
The aggregate data reveals a clear pattern of intrusion-oriented operations originating from cloud infrastructure, a common tactic employed by threat actors to blend malicious traffic with legitimate cloud services. Of the 20 most recent reports, 19 categorise the activity as general hacking attempts while one flags IoT-targeted behaviour, suggesting the address may be used in campaigns against both traditional server infrastructure and internet-of-things devices. Suricata intrusion-detection sensors flagged anomalous protocol mismatches in bidirectional traffic and identified SSH sessions being established over non-standard ports, a technique frequently used to evade basic firewall rules and network monitoring. The volume of reports over a six-month window indicates persistent, automated scanning rather than isolated opportunistic probes.
The dominant hacking classification encompasses a broad range of intrusion techniques including vulnerability exploitation, credential attacks, and unauthorized access attempts, all of which pose a direct threat to any exposed service. The specific detection of SSH traffic traversing unusual ports strongly implies attempts to bypass default security configurations that only monitor standard port 22, potentially facilitating remote access to compromised systems or lateral movement within networks. When combined with IoT-targeting indicators, this activity profile suggests a multi-vector reconnaissance and exploitation operation capable of compromising both conventional servers and poorly secured connected devices.
Network operators should treat IP 198.235.24.211 as hostile and implement immediate blocking at the firewall or intrusion-prevention layer. Services exposing SSH, Telnet, or other remote-access protocols should enforce key-based authentication, implement fail2ban or equivalent brute-force mitigation, and restrict access by IP allowlist where feasible. IoT and ICS devices require network segmentation from general infrastructure, firmware updates, and replacement of default credentials to reduce exposure to the IoT-targeting component of this threat. Continuous monitoring of unusual port activity and protocol anomalies will help detect similar scanning behaviour from adjacent addresses within the same cloud ASN.