Substantial Risk
IP 198.235.24.216 is a high-risk address linked to confirmed hacking activity, reconnaissance port scanning, and potential host compromise indicators originating from Google Cloud Platform infrastructure in the United States. With a threat level of 8 out of 10 and 157 independent abuse reports gathered from 20 automated honeypot sensors over an eleven-month observation window, this IP demonstrates persistent malicious behavior that warrants immediate defensive attention.
The detection data reveals a moderate but steady activity frequency of 5 out of 10, with the first reports dating to August 2025 and continued activity through June 2026. The dominant threat classification is Hacking, accounting for 18 of the most recent reports, supplemented by isolated Exploited Host and Port Scan designations. Observed attack patterns include malware and exploit delivery attempts, established attack connections, and Ciscoasa-specific reconnaissance probes targeting network security appliances. The 80 percent confidence score reflects strong corroboration across multiple sensor types, indicating that the activity observed is not spurious or misattributed traffic but genuine hostile operations.
The concentration of hacking activity alongside port scanning reconnaissance suggests this address is being used to systematically identify and exploit vulnerabilities in target systems. The Ciscoasa probe pattern is particularly noteworthy, as it indicates deliberate targeting of firewall and security hardware, potentially as a precursor to more sophisticated intrusion campaigns. Alternatively, the Exploited Host classification raises the possibility that this cloud IP address may itself belong to a compromised system that has been weaponized by threat actors without the legitimate operator's knowledge, making notification to Google Cloud Platform an important step.
Network defenders should block IP 198.235.24.216 at the perimeter firewall level and implement strict inbound traffic filtering. Authentication endpoints such as SSH, RDP, and web login portals should be hardened through rate limiting, strong credential requirements, and where possible, key-based or multi-factor authentication. Tools like fail2ban can automate dynamic blocking of repeated attack patterns. Organizations with Ciscoasa devices should ensure firmware is current and consider restricting management interface exposure to known administrative subnets. Finally, reviewing honeypot and network flow logs for any matching connection attempts will help determine whether internal systems have been targeted.