Critical Alert
IP 34.76.111.153 is a critical-risk address with a 10/10 threat level and 94% confidence, linked to 260 abuse reports dominated by general hacking activity originating from Google Cloud Platform infrastructure in Belgium. The IP has been flagged by 20 automated honeypot sensors across multiple detection categories spanning hacking, IoT targeting, exploited-host behavior, and web application attacks, indicating a versatile and persistent threat actor operating from cloud-hosted infrastructure.
Community reports and automated honeypot sensors recorded this address consistently between March 2026 and May 2026, with 18 of the most recent reports categorizing the activity as general hacking attempts. Additional reports document IoT-targeted probing, exploited-host behavior, and web application reconnaissance, bringing the total abuse tally to 260 independent filings. The attack-pattern data extracted from sensor telemetry includes attack connections, IoT-targeted probes, malware and exploit activity, and web application reconnaissance. The presence of this IP within AS396982 operated by Google Cloud Platform places the activity within a major cloud hosting environment, a network segment frequently abused for scanning campaigns due to its perceived legitimacy and geographic flexibility. Belgium's network infrastructure serves as the geographic anchor for these operations, though the cloud-based origin makes attribution to specific actors challenging.
The dominant hacking category encompasses automated intrusion attempts, unauthorized access scans, and exploitation of vulnerable services exposed to the internet. The concurrent IoT-targeted activity suggests this actor systematically probes for weakly secured connected devices, while the exploited-host classification indicates the possibility that this IP may itself be part of a compromised infrastructure being leveraged without the operator's knowledge. Web application probing signals active reconnaissance against publicly accessible software stacks. For organizations running internet-facing services, this combination of scanning vectors creates tangible risk of credential compromise, device exploitation, or successful web application intrusion. The sustained two-month reporting window and high report volume underscore that this is not incidental noise but organized, automated hostile activity.