High Risk
IP 198.235.24.246 is a critical-risk address operating from Google Cloud infrastructure in the United States that has accumulated 242 abuse reports across 20 independent automated honeypot sensors between August 2025 and May 2026, indicating sustained, high-volume malicious activity with a confidence score of 78 percent.
The 242 total reports directed at this single IP represent significant sustained attention from the defensive community, with 18 reports categorizing the activity as general hacking intrusion attempts, supplemented by isolated web application targeting and evidence suggesting the IP itself may have been leveraged as an attack platform. The detection span of approximately ten months demonstrates persistent rather than opportunistic behavior, and the volume of distinct reporting sources confirms this is not an isolated anomaly but rather a widely observed threat pattern. Google Cloud Platform IP ranges are frequently exploited by threat actors precisely because cloud traffic may bypass naive blocklists, making infrastructure attribution an important contextual factor for defenders evaluating this address.
The dominant "Hacking" classification encompasses unauthorized access attempts, vulnerability exploitation, and intrusion activity against exposed services, while the web application attack component indicates probing for application-layer weaknesses such as those identified in the OWASP Top 10. The presence of an "Exploited Host" classification raises the possibility that this address may be serving as a compromised node in a larger attack infrastructure, effectively doubling the risk profile since defenders may be encountering secondary rather than primary attack traffic. The reported attack patterns involving connection attempts, web application probing, and exploit activity collectively suggest a versatile threat actor capable of multiple intrusion methodologies.
Site operators with exposed services should immediately block IP 198.235.24.246 at the network perimeter or firewall level and configure automated blocking via tools such as fail2ban or similar threshold-based mechanisms to prevent repeated contact attempts. Deploying a Web Application Firewall provides critical protection against the application-layer probing component of this threat. All exposed services should be audited for patch currency and configuration hardening, with particular attention to services that would be natural targets for SSH, HTTP, or database attack vectors. Defenders should monitor logs for any successful connections from this address and consider reporting the activity to Google Cloud Platform's abuse team if the traffic appears to originate from or target cloud-hosted infrastructure.