Critical Alert
IP address 35.203.210.72 is a high-risk threat actor address with a maximum threat score of 10 out of 10, linked to persistent hacking activity including intrusion attempts and exploitation of vulnerable services. The address has accumulated 294 total abuse reports, with 20 recent reports specifically categorizing the activity as hacking. Detection occurred through 20 automated honeypot sensors, indicating coordinated scanning and attack behavior originating from this source.
The IP is registered to Google Cloud Platform (ASN AS396982) and geolocates to the United Kingdom, though cloud infrastructure means the physical origin of the operator may differ from the registered location. The address was first reported in August 2025 and remains active through June 2026, representing approximately ten months of sustained hostile activity. With an activity frequency rating of 5 out of 10, the threat demonstrates consistent rather than burst-pattern behavior, suggesting a methodical campaign rather than opportunistic scanning. The 73% confidence score reflects reliable attribution despite the typical challenges of tracing cloud-hosted infrastructure.
The dominant threat category of hacking encompasses unauthorized access attempts, vulnerability probing, and exploitation of misconfigured or outdated services exposed to the internet. The reported attack pattern of "attack connection" indicates this address is actively establishing sessions with target systems for purposes of intrusion. For organizations running exposed services, this translates to a concrete risk of credential compromise, data exfiltration, or pivoting into internal networks if initial access is achieved. The sustained nature of the reports suggests this is not random scanning but targeted reconnaissance activity.
Site operators should treat connections from 35.203.210.72 as hostile and block the address at the network perimeter or firewall level. Implementing strict rate-limiting on authentication endpoints and enforcing strong credential policies reduces the effectiveness of any intrusion attempts. Deploying intrusion detection systems and monitoring for repeated connection attempts from this IP helps identify targeted systems. Tools such as fail2ban can automatically ban addresses exhibiting brute-force patterns, and maintaining current patches across all internet-facing services eliminates common exploitation vectors.