Critical Alert
IP 35.203.211.62 is a high-risk address with a perfect threat score of 10/10 that has been linked to unauthorized access attempts, scoring 199 abuse reports from automated honeypot sensors since August 2025.
The address sits within Google Cloud Platform's network (ASN AS396982) and is geolocated to Great Britain, though cloud infrastructure often obscures true actor origins. The report volume of 199 incidents across an approximately nine-month window (August 2025 to May 2026) with an activity frequency rated at 5/10 indicates persistent, methodical reconnaissance rather than opportunistic scanning. All 20 most recent threat categorisations flag the address for hacking activity, and detection data shows an active SSH session established on an unusual port, a common tactic used to evade signature-based detection. The 80% confidence score reflects high certainty in the attribution of this traffic as malicious, based on patterns observed across the honeypot sensor network.
Hacking activity encompasses automated exploitation attempts, vulnerability probing and credential-based intrusion vectors. The specific detection of an SSH session on a non-standard port strongly suggests the operator is conducting brute-force authentication attacks or attempting to establish persistent access while avoiding standard port monitoring. Cloud-hosted sources like this IP are frequently leveraged because they benefit from reputational trust from legitimate traffic, making initial network blocks less reliable and increasing the likelihood of reaching exposed services.
Site operators with exposed SSH or similar authentication portals should immediately block or challenge traffic from this address. Implementing fail2ban or equivalent log-based auth failure thresholds will automatically ban repeated offenders. Enforcing key-based authentication over password auth, limiting login attempts and monitoring for unusual port usage on SSH services will substantially reduce exposure to this intrusion pattern.