AbuseIPDB » 34.52.153.180
34.52.153.180 was found in our database!
This IP was reported 9 times. Confidence of
Abuse
is 56% : ?
ISP
Google LLC
Usage Type
Data Center/Web Hosting/Transit
ASN
AS396982
Hostname(s)
180.153.52.34.bc.googleusercontent.com
Domain Name
google.com
Country
๐ง๐ช
Belgium
City
Brussels, Brussels Capital
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 34.52.153.180 :
This IP address has been reported a total of
9
times from
9 distinct
sources.
34.52.153.180 was first reported on
July 27th 2026 , and the most recent report was
3 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
brantknudson.org
2026-07-27 07:00:26
(3 hours ago)
Client sent invalid (non-HTTP) message to honeypot web server:
34.52.153.180 - - [27/Jul/2026:02:00: ...
show more
Client sent invalid (non-HTTP) message to honeypot web server:
34.52.153.180 - - [27/Jul/2026:02:00:26 -0500] "\x16\x03\x00\x00i\x01\x00\x00e\x03\x03U\x1C\xA7\xE4random1random2random3random4\x00\x00\x0C\x00/\x00" 400 166 "-" "-" "-" ""
show less
Web App Attack
Port Scan
๐จ๐ฆ
smithoo4
2026-07-27 05:25:39
(5 hours ago)
34.52.153.180 - - [27/Jul/2026:01:25:38 -0400] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
34.52.153.180 - - [27/Jul/2026:01:25:38 -0400] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
34.52.153.180 - - [27/Jul/2026:01:25:38 -0400] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x897\xF0<\x93\x9C'\x9F+\x15\xF9\xCC\x1B\xEA\x11\x9C\x1F\x0E\xF3\x12\xE3\xBB\x92\x88\x84\xEA\xC5\xE1\x22\xCA\x1D\xB2 \xC6\x87\x0E>\xB4\xF0H9:\xDA\xD9Y\x01B\xAE\xCF\x15\x1A\x90\x0B\xCF!\xD7Cx\x5C\x90Q,\xB2\xE7\x9A\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
...
show less
Port Scan
Bad Web Bot
๐บ๐ธ
Starburst SysOp Team
2026-07-27 04:13:02
(6 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-4)
Hacking
Bad Web Bot
๐ฏ๐ต
mkaraki
2026-07-27 04:03:55
(6 hours ago)
1785125034 # Service_probe # SIGNATURE_SEND # source_ip:34.52.153.180 # dst_port:80
...
Port Scan
๐บ๐ธ
antlac1
2026-07-27 03:49:26
(7 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
nyt
2026-07-27 02:36:27
(8 hours ago)
Empty UA + error
Web App Attack
๐ธ๐ฌ
WMK965
2026-07-27 02:33:18
(8 hours ago)
34.52.153.180 - - [27/Jul/2026:10:33:09 +0800] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03$\xA2\xD ...
show more
34.52.153.180 - - [27/Jul/2026:10:33:09 +0800] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03$\xA2\xD9" 400 154 "-" "-" "-"
34.52.153.180 - - [27/Jul/2026:10:33:14 +0800] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 154 "-" "-" "-"
34.52.153.180 - - [27/Jul/2026:10:33:17 +0800] "$&\x1A\x83\x9EH\xE8\x8A\x07\x0EPr\xA00\x85\xCDp\xB2\x05\x89j\xFC\x1F\xA54>H\xE9\x12\x88\x0FL\x9DJ\x1Bm\xC5\x07\x1E|F\x80T\xAF9G>b\xD9\xB0\xAD\xFF\xA1\xAC2\xF4\xDF~\xB4\x8CY\xBD\xC6\xB8" 400 154 "-" "-" "-"
show less
Port Scan
Web App Attack
๐ง๐ท
mubusys.com
2026-07-27 02:29:42
(8 hours ago)
34.52.153.180 - - [26/Jul/2026:23:29:30 -0300] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xF8\x06 ...
show more
34.52.153.180 - - [26/Jul/2026:23:29:30 -0300] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xF8\x06\xF2-r\xDE=\xC0\xD6\xCB\xBCPpk\xC3\xBC\x88\xF8\x07\xE2N\xC8]\xBE\x16\x07\xD5$\xE5P\x9F\x15 v\xE0}\xE0\x9B\x1F\xACP{^\xAC?\x9C?\xE7-\x91\xC3;;\x8C\xC1\xD5R\xB5\xE0\xE7\x89\xAE\xB1\xD5v\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 157 "-" "-" "-"
34.52.153.180 - - [26/Jul/2026:23:29:36 -0300] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 157 "-" "-" "-"
show less
Hacking
Brute-Force
๐ฌ๐ท
setupgr
2026-07-27 02:21:38
(8 hours ago)
(mod_security) mod_security (id:9999001) triggered by 34.52.153.180 (BE/Belgium/Brussels Capital/Bru ...
show more
(mod_security) mod_security (id:9999001) triggered by 34.52.153.180 (BE/Belgium/Brussels Capital/Brussels/-/[AS396982 GOOGLE-CLOUD-PLATFORM]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:21:37.298093 2026] [security2:error] [pid 3049:tid 3148] [client 34.52.153.180:48182] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^154\\\\.57\\\\.7\\\\.73$" at REQUEST_HEADERS:Host. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "155"] [id "9999001"] [msg "Direct incoming request to server shared IP blocked by admin"] [hostname "154.57.7.73"] [uri "/"] [unique_id "ambAsW-J_6ZEYqMhZPhgigAAA4Q"]
show less
Port Scan
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: