This IP address has been reported a total of
9
times from
9 distinct
sources.
136.69.252.76 was first reported on
September 25th 2026 , and the most recent report was
4 days ago .
In the last 60 days, the top reporter locations were:
Australia
with 2
reports;
United States of America
with 2
reports;
Germany
with 1
report.
The most common categories in these recent reports were:
Web App Attack
5
times;
Port Scan
4
times;
Hacking
3
times;
Brute-Force
2
times;
Bad Web Bot
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-10-07 16:20:35
(4 days ago)
(CT) IP 136.69.252.76 (76.252.69.136.bc.googleusercontent.com) found to have 14 connections; Ports: ...
show more
(CT) IP 136.69.252.76 (76.252.69.136.bc.googleusercontent.com) found to have 14 connections; Ports: *; Direction: inout; Trigger: CT_LIMIT; Logs: tcp: 136.69.252.76:57082 -> 31.134.201.55:80 (TIME_WAIT)
tcp: 136.69.252.76:57066 -> 31.134.201.55:80 (TIME_WAIT)
tcp: 136.69.252.76:59782 -> 31.134.201.55:443 (TIME_WAIT)
tcp: 136.69.252.76:51456 -> 31.134.201.55:443 (TIME_WAIT)
tcp: 136.69.252.76:37321 -> 31.134.201.55:443 (TIME_WAIT)
tcp: 136.69.252.76:57014 -> 31.134.201.55:80 (TIME_WAIT)
tcp: 136.69.252.76:57048 -> 31.134.201.55:80 (TIME_WAIT)
tcp: 136.69.252.76:59852 -> 31.134.201.55:443 (TIME_WAIT)
tcp: 136.69.252.76:57022 -> 31.134.201.55:80 (TIME_WAIT)
tcp: 136.69.252.76:59770 -> 31.134.201.55:443 (TIME_WAIT)
tcp: 136.69.252.76:57050 -> 31.134.201.55:80 (TIME_WAIT)
tcp: 136.69.252.76:57044 -> 31.134.201.55:80 (TIME_WAIT)
tcp: 136.69.252.76:14895 -> 31.134.201.55:80 (TIME_WAIT)
tcp: 136.69.252.76:59856 -> 31.134.201.55:443 (TIME_WAIT)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-07 10:13:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.69.252.76 (76.252.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.69.252.76 (76.252.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:12:57.701028 2026] [security2:error] [pid 3946:tid 3946] [client 136.69.252.76:46588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmcnow.net"] [uri "/wp-config.php"] [unique_id "asYbKbATDFz5rjAwb-MX9wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-10-07 05:37:34
(4 days ago)
(mod_security) mod_security (id:11000011) triggered by 136.69.252.76 (US/United States/Oregon/The Da ...
show more
(mod_security) mod_security (id:11000011) triggered by 136.69.252.76 (US/United States/Oregon/The Dalles/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:37:32.667806 2026] [security2:error] [pid 1055332:tid 1055494] [client 136.69.252.76:60778] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 76.252.69.136.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "www.ftiaxtomonosou.gr"] [uri "/"] [unique_id "asXanFkRrL42I4uaBs-shwAAA9Y"]
show less
Port Scan
๐ฆ๐บ
Bay13
2026-10-06 18:51:16
(4 days ago)
CrowdSec:custom/http-probing
Web App Attack
๐ฆ๐บ
FireGuard Server
2026-10-06 18:45:03
(4 days ago)
Blocked by os-abuseipdb; 36 hits, proto=tcp, ports=80
Port Scan
Hacking
๐บ๐ธ
Kurtbaby
2026-10-06 13:01:00
(5 days ago)
Port Scan
Hacking
๐ฉ๐ช
LRob
2026-10-03 11:18:58
(1 week ago)
Secret file probe | method: GET | path: /wp-config.php | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x6 ...
show more
Secret file probe | method: GET | path: /wp-config.php | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0
show less
Hacking
Web App Attack
๐ท๐ด
gtheo99
2026-10-01 05:23:02
(1 week ago)
Automated cPanel/WHM login brute-force from Google Cloud host; dropped at firewall (ports 2082-2087) ...
show more
Automated cPanel/WHM login brute-force from Google Cloud host; dropped at firewall (ports 2082-2087) on cpanel1.teron.ro
show less
Brute-Force
Web App Attack
๐ธ๐ช
KIDOS
2026-09-25 07:18:11
(2 weeks ago)
IIS malicious activity: high_400_error_rate (100% of requests are 400 errors)
Web App Attack
Showing 1 to
9
of 9 reports