Maximum Danger
IP address 35.195.138.45, allocated to Google LLC under autonomous system AS396982 and geolocated to Belgium, presents a critical threat with a maximum threat level of 10 out of 10 and a confidence rating of 94 percent based on 287 abuse reports sourced from 20 automated honeypot sensors. The address was first reported in March 2026 and remained active through June 2026, demonstrating sustained malicious behavior over a multi-month window. Activity frequency has been assessed at 8 out of 10, indicating persistent and aggressive engagement with target infrastructure.
The overwhelming majority of recent reports classify this address under Hacking activity, supplemented by Exploited Host and Web App Attack categorizations. Observed attack patterns include repeated connection attempts, web application reconnaissance probes, and Suricata detection alerts flagging potentially unsafe SMBv1 protocol usage consistent with malware or exploit delivery. The presence of SMBv1-related signatures strongly suggests the IP is involved in propagating ransomware families or conducting lateral movement within enterprise networks, as this deprecated protocol remains a favoured initial access vector for threat actors seeking to exploit unpatched Windows environments.
Organizations with internet-facing services, particularly Windows-based systems utilizing SMB, should treat this IP as a confirmed hostile actor requiring immediate defensive action. The sustained volume of reports and diversity of attack vectors indicate this is not opportunistic scanning but rather a systematic campaign likely originating from a compromised infrastructure node being leveraged as a pivot point. The Belgian network assignment raises the possibility that the underlying host has been commandeered without the knowledge of its legitimate operator, which is consistent with the Exploited Host classification alongside the malware-related signatures observed.
Site operators should block IP 35.195.138.45 at the network perimeter, deploy or tighten firewall rules governing inbound SMB traffic on ports 139 and 445, and ensure all Windows hosts are fully patched against known SMB vulnerabilities. Implementing fail2ban or equivalent dynamic blocking tools can automate the defensive response based on continued detection. Additionally, reviewing logs for any successful connections originating from this address and considering notification to the hosting provider regarding the compromised or malicious host represents prudent incident-response measures.