Notable Threat
IP 198.235.24.93 is a critical-risk address with a threat level of 10/10 that has generated 181 abuse reports across automated honeypot sensors, indicating sustained and aggressive malicious activity originating from Google Cloud Platform infrastructure in the United States. This IP warrants immediate blocking consideration for any organization exposing services to the internet.
Analysis of the reported data reveals that this address was first flagged in August 2025 and remained active through May 2026, amassing a substantial volume of reports from 20 distinct honeypot sensors. The overwhelming majority of threats classified as Hacking activity, complemented by isolated Web Application Attack signatures, demonstrates an attacker leveraging cloud-hosted infrastructure to conduct probing and exploitation attempts at scale. Detection mechanisms captured network anomalies consistent with connection-based probing, including Suricata alerts indicating malformed TCP acknowledgment packets and web application reconnaissance activity targeting exposed services.
The Hacking activity detected against this IP represents unauthorized access attempts and potential exploitation of vulnerable services, while the Web Application Attack component signals interest in exploiting application-layer weaknesses commonly associated with OWASP Top 10 vulnerabilities. The presence of broken ACK packet anomalies suggests the host may be engaged in TCP state-tracking evasion techniques or conducting reconnaissance to map firewall and intrusion detection system configurations before launching more sophisticated attacks.
Organizations with internet-facing services should implement immediate defensive measures including blocking or rate-limiting this IP at the network perimeter, deploying or updating web application firewall rules to counter probing attempts, and hardening authentication mechanisms with tools such as fail2ban or equivalent solutions to automatically block repeated connection attempts. Regular security audits and patch management for exposed services remain essential to reduce the attack surface that this IP is actively targeting.