Severe Risk
IP 35.200.201.144 is a critical-risk address operating from Google Cloud Platform infrastructure in India that has generated 446 abuse reports across a six-month period, with automated honeypot sensors flagging it predominantly for sustained SSH brute-force intrusion attempts and confirmed exploitation activity. The threat level of 10/10 and activity frequency rating of 8/10 reflect a persistent, high-confidence pattern of automated credential-guessing attacks originating from this address, which may itself be a compromised cloud instance or a rented attack platform within the Google network.
Analysis of the 446 reports spanning November 2025 through May 2026 reveals that 20 separate honeypot sensors detected this IP repeatedly attempting to establish SSH connections and execute brute-force authentication attacks. The dominant threat categories recorded were SSH attacks (19 recent reports) and hacking activity (18 recent reports), with 3 separate reports classifying this address as an exploited host — indicating that 35.200.201.144 may be functioning as an attack platform without its owner's knowledge. The network operator AS396982 (GOOGLE-CLOUD-PLATFORM) hosts millions of instances globally, and abuse of this infrastructure for credential stuffing is a well-documented pattern in threat intelligence.
SSH brute-force attacks automated honeypot sensors documented on this IP involve repeated, high-speed attempts to authenticate to exposed SSH services by cycling through common username-password combinations or credential dictionaries. The Suricata alerts confirm active SSH sessions were established on expected ports, suggesting the attacker successfully authenticated or was actively probing session vulnerabilities. For organizations running publicly accessible SSH services, such an IP represents a direct pathway to server compromise, data exfiltration, lateral movement within networks, or recruitment into botnets — particularly given the "exploited host" classification suggesting this address itself may be controlled by threat actors.
Site operators should treat 35.200.201.144 as a confirmed malicious source and block it at the network perimeter or firewall level. SSH services should be hardened by disabling root login, changing the default port from 22, and implementing key-based authentication exclusively to eliminate password-based attack surface. Deploying automated tools such as fail2ban to detect and temporarily ban repeated authentication failures will substantially reduce the effectiveness of such brute-force campaigns. Regular monitoring of authentication logs for source IP 35.200.201.144 and promptly patching SSH daemons will further mitigate risk from this persistent threat actor operating within Google Cloud infrastructure.