Critical Threat
IP 34.76.107.251 is a critical-risk address operating from a Google LLC cloud infrastructure in Belgium (AS396982), with 251 abuse reports filed through automated honeypot sensors over approximately four months, making it a high-priority candidate for blocking on any exposed network perimeter.
The data collected between March and June 2026 reveals sustained hostile activity across multiple detection sources, with a threat level rated 10 out of 10 and a confidence score of 94 percent indicating highly reliable attribution. Hacking activity dominates the reported categories, accounting for 19 of the categorized incidents, while evidence of the host itself being compromised and weaponized appeared in 2 reports, and targeted web application probing featured in 1 additional report. Network inspection logs from honeypot sensors flagged multiple anomalous indicators, including protocol negotiation mismatches, potentially unsafe SMB version 1 usage consistent with malware or exploit delivery, and direct reconnaissance probes against web application honeypots. The volume and consistency of these reports over a four-month window confirm this is not isolated noise but sustained, deliberate hostile infrastructure.
The dominant hacking activity observed on this IP represents the full spectrum of intrusion tradecraft: automated exploitation attempts, vulnerability scanning, and credential access probes that systematically probe internet-facing services for entry points. The detection of SMB version 1 protocol activity is particularly concerning as this legacy protocol has a well-documented history of being leveraged in ransomware and lateral-movement campaigns. The presence of web application probe signatures indicates the address is actively scanning for OWASP Top 10 class vulnerabilities such as injection flaws and insecure direct object references. When combined with the "Exploited Host" classification, the evidence strongly suggests this Google Cloud IP has itself been compromised and is being operated as a cutout node by threat actors to anonymize their operations while conducting third-party attacks.
Any operator with services exposed to the internet should immediately block 34.76.107.251 at the network edge and monitor logs for any successful connections originating from this address. Implement strict rate-limiting on authentication endpoints and deploy fail2ban or equivalent intrusion-prevention tools to automatically ban repeat offenders. Ensure all internet-facing applications are patched against known SMB vulnerabilities and consider deploying a web application firewall to mitigate application-layer probing. Finally, organizations utilizing Google Cloud Platform should report this IP to Google Cloud's abuse team so the legitimate tenant or compromised resource can be identified and remediated.