Extreme Threat
IP 195.184.76.122 represents a critical threat with a maximum threat-level score of 10 out of 10, supported by 441 abuse reports from automated honeypot sensors detecting persistent hacking activity over an eight-month window between October 2025 and June 2026. The address is registered in the United States and routed through ASN AS213412, operated by ONYPHE SAS, with an activity frequency rating of 8 out of 10 indicating sustained, repeated offensive operations rather than isolated probing.
Threat intelligence gathered from 20 distinct honeypot sensor sources confirms consistent engagement with this IP address across multiple detection points, yielding a 73 percent confidence score in the assessment of malicious intent. The volume of reports—441 total—and the consistently high activity frequency establish this as a prolific source of unauthorized access attempts rather than opportunistic scanning. The eight-month reporting span demonstrates persistent targeting behaviour, with the address maintaining its offensive posture throughout the observation period.
The dominant threat classification for IP 195.184.76.122 centres on general hacking activity, encompassing intrusion attempts, exploitation of vulnerabilities and repeated unauthorized access probes against exposed services. This pattern of sustained, automated attack connections poses a concrete risk to any publicly accessible system, particularly those with weak authentication configurations, unpatched software or exposed administrative interfaces. The consistent detection across multiple independent sensors indicates the address is actively contributing to hostile automated campaigns rather than passively appearing in logs.
Site operators should immediately block this IP at the network perimeter and consider blocking the entire AS213412 prefix if broader abuse patterns emerge from that operator's address space. Implementing rate-limiting on authentication endpoints and enforcing multi-factor authentication for all remote-access services significantly reduces the effectiveness of such intrusion attempts. Deploying defensive tools such as fail2ban to automatically detect and temporarily block repeated failed-login patterns can neutralise automated attack vectors. Continuous log analysis for connections originating from this address will help identify any successful access attempts and support rapid incident response.