Extreme Threat
IP 198.235.24.79 is a maximum-risk address originating from Google Cloud Platform infrastructure in the United States that has been extensively linked to automated hacking activity, with 173 abuse reports filed across automated honeypot sensors over a ten-month observation window between August 2025 and May 2026. The IP carries a threat level of 10 out of 10, indicating it poses a severe risk to any exposed services it targets.
Network routing data confirms 198.235.24.79 belongs to AS396982 operated by Google Cloud Platform, a major cloud hosting provider frequently abused by threat actors due to its extensive global IP space and reputation for legitimate enterprise use. The 173 total reports were generated by 20 distinct automated honeypot sensors, with 20 categorised as hacking activity and 2 as exploited-host behaviour. The activity frequency rating of 4 out of 10 suggests consistent but not constant targeting, while the 80% confidence score reflects substantial corroboration across multiple detection sources. The combination of high-volume honeypot hits and evidence of potential host compromise makes this address particularly dangerous in abuse-db lookups and IP reputation checks.
The dominant hacking classification encompasses automated intrusion attempts, vulnerability exploitation and unauthorized access scanning against exposed services. Sensor logs documented attack patterns consistent with Redis service exploitation, where threat actors probe for misconfigured Redis deployments to achieve remote code execution or data exfiltration. The presence of exploited-host indicators suggests this IP may itself be running malicious tooling without the knowledge of its cloud operator or the compromised instance owner. Any organisation operating Redis instances, container environments or exposed API endpoints should treat this IP as an active threat vector requiring immediate blocking or monitoring.
Site operators should implement immediate blocking of 198.235.24.79 at the firewall or network perimeter level, and configure automated tools such as fail2ban to dynamically ban repeat offenders matching this threat profile. Redis deployments should enforce authentication, bind to localhost only and never run with root privileges. Consistent patch management, monitoring of authentication logs for brute-force patterns and deployment of intrusion-detection signatures for Redis exploitation attempts will significantly reduce exposure to this category of automated attack.