Notable Threat
IP 198.235.24.70 is a high-risk address operating from Google Cloud Platform infrastructure in the United States, with a threat level of 8/10 and 190 reports filed over approximately ten months of sustained malicious activity. The dominant threat category is hacking activity, accounting for the vast majority of recent reports, indicating that this IP has been systematically attempting unauthorized access and intrusion against exposed services.
Detection data from 20 automated honeypot sensors and community submissions documents a persistent campaign from August 2025 through June 2026, reflecting an activity frequency rating of 6/10. The address resides within AS396982, Google Cloud Platform's globally distributed network, and Suricata intrusion-detection signatures have flagged anomalous SMTP protocol behavior, broken stream acknowledgment packets, and active SSH sessions on non-standard ports. This combination of protocol-level irregularities and credential-attack patterns indicates coordinated exploitation attempts rather than opportunistic scanning.
The hacking classification encompasses multiple intrusion vectors, including SMTP abuse consistent with spam relay or phishing infrastructure testing and SSH session establishment patterns indicative of brute-force or credential-stuffing campaigns. When hosted on cloud infrastructure like Google Cloud Platform, such activity often leverages the reputation of major providers to bypass basic IP reputation filters. The broken acknowledgment packets suggest either evasive technique testing or unstable connectivity from a high-volume attack source. Each successful intrusion could result in unauthorized system access, data exfiltration, or further lateral movement within a network.
Site operators should implement immediate blocking or rate-limiting measures for traffic originating from this address and similar untrusted sources. Deploying automated defensive tools such as fail2ban can actively detect and ban IPs exhibiting repeated authentication failures. Hardening SSH configurations by disabling password-based authentication, enforcing key-based access, and restricting login attempts significantly reduces the effectiveness of credential attacks. Regular monitoring of Suricata and similar intrusion-detection alerts, particularly for protocol anomalies and unexpected service sessions, enables rapid identification of ongoing exploitation attempts.