Extreme Threat
IP 34.78.23.28 is a high-risk address operating from Belgian infrastructure under Google LLC (ASN AS396982) that has generated 155 abuse reports between April and June 2026, indicating sustained malicious activity with a 94% confidence score and a threat level of 10/10. The dominant threat category is general hacking activity, supported by evidence of SMBv1 protocol exploitation detected through automated honeypot sensors. This IP presents a clear and present danger to any exposed services.
The volume of reports and consistent activity frequency of 8/10 over a three-month window demonstrates persistent, deliberate targeting rather than opportunistic scanning. All 20 report sources originate from automated honeypot infrastructure, which detected connection attempts consistent with malware and exploit delivery patterns. The additional classification of this address as an exploited host suggests the IP itself may be compromised and operating under attacker control without the owner's knowledge, transforming it into an unwitting attack platform. The Suricata signature alert specifically flagged potentially unsafe SMBv1 protocol usage associated with malware and exploit activity, a known attack vector for lateral movement and remote code execution.
The concentration of hacking activity against exposed services means this IP is actively attempting to exploit vulnerabilities, gain unauthorized access, or deploy malicious payloads. SMBv1 exploitation is particularly concerning as it has been historically leveraged in destructive ransomware campaigns and worm-style propagation. For network operators with services exposed to this address, the real-world risk includes data breach, system compromise, and infection spread across internal infrastructure. The 94% confidence score indicates overwhelming evidence that this IP poses a genuine threat.
Site operators should immediately block IP 34.78.23.28 at the firewall level and implement strict inbound connection filtering. SMB and related file-sharing ports should be blocked or restricted to trusted networks only. Deploying or strengthening brute-force protection tools such as fail2ban alongside robust intrusion detection monitoring will help identify and neutralize repeated attack patterns. Organizations should also consider notifying the hosting provider about the potential compromised host to facilitate takedown of the attack platform.