High Risk
IP 35.205.235.254, a Google Cloud Platform address registered to Belgium, presents a high-risk threat profile with a threat level of 8/10 based on 206 total abuse reports spanning August 2025 to February 2026. This address has been flagged primarily for hacking activity, with supplementary detections for bad web bot behavior and exploited host indicators. The elevated threat rating combined with a moderate confidence score of 63 percent indicates that analysts have substantial evidence the IP is actively engaged in malicious operations, though attribution remains somewhat uncertain. Despite a low activity frequency rating of 0/10, the volume of reports suggests concentrated or burst-style offensive operations rather than sustained continuous traffic.
The detection data reveals that this Google Cloud IP was identified predominantly through automated honeypot sensors, accounting for 19 of 20 total report sources, with a single community-sourced report corroborating the automated findings. The reported threat categories break down as 18 hacking incidents, one bad web bot report, and one exploited host indicator. Attack pattern analysis shows automated scanner activity targeting NGINX infrastructure, honeypot event triggers, and malware or exploit behavior. The AS396982 autonomous system is operated by Google Cloud Platform, which means the source infrastructure is a major cloud provider rather than a residential or business ISP, raising the possibility that a compromised cloud resource is being weaponized as an attack platform.
The dominant hacking classification encompasses broad intrusion attempts, vulnerability exploitation, and unauthorized access probing. Combined with the bad web bot detection, this IP appears to conduct automated reconnaissance and vulnerability scanning against web-facing services, systematically probing for exploitable conditions while ignoring standard bot directives. The exploited host flag suggests the address itself may be running on a compromised or abused cloud instance whose legitimate operator is unaware their infrastructure is being used for offensive operations. This combination creates a dual risk: the IP poses a direct threat to exposed services, and it may represent a hijacked cloud resource whose owner could themselves be a victim of compromise.