IP Address

176.65.148.95

IPv4 Public
NL NL
AS51396
Pfcloud UG
195 Reports
This IP is under Observation Suspicious activity detected - monitor closely
10/10 Threat
24% Confidence
195 Reports
Is this your IP address? If the cause is fixed, you can request removal. Free of charge, usually decided within 48 hours. Request delisting

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 5% Most Dangerous
NL
NL Location
Pfcloud UG ASN 51396
195 Reports
Honeypot Data Source

Severe Risk

IP 176.65.148.95 is a critical-risk address linked to persistent hacking activity, operated through AS51396 (Pfcloud UG) in the Netherlands, with 181 documented abuse reports spanning October 2025 through April 2026. Despite a low activity frequency score, the sustained volume of automated honeypot detections and a maximum threat-level rating make this IP a high-priority concern for any exposed infrastructure. The consistent focus on hacking-related intrusion attempts signals an ongoing automated threat rather than isolated opportunistic scanning.

Network intelligence places 176.65.148.95 within a Pfcloud UG autonomous system, a hosting provider whose infrastructure is frequently leveraged for dynamic threat actors due to the relative anonymity of cloud-provisioned IPs. All 181 reports originate exclusively from automated honeypot sensors, with the 20 most recent submissions uniformly categorised as hacking activity. The six-month reporting window demonstrates persistent activity rather than a single incident, while the 70% confidence score reflects standard uncertainty in attributing hosting-provider IP ranges to specific threat actors. The discrepancy between low activity frequency and high report volume suggests intermittent but deliberate targeted campaigns rather than continuous broad scanning.

The dominant hacking classification encompasses automated intrusion attempts, vulnerability exploitation and credential-based access attempts against internet-facing services. Attackers leveraging such IPs typically conduct systematic scans for exposed SSH, RDP, database or web-application endpoints, following detection with brute-force attempts or exploitation of known vulnerabilities. Successful compromise from this category of threat can result in data exfiltration, cryptomining malware deployment, botnet recruitment or lateral movement through connected systems, with impacts potentially cascading beyond the initially targeted host.

Administrators should immediately block or aggressively rate-limit traffic originating from 176.65.148.95 at the network perimeter using firewall rules or access-control lists. Implement automated authentication-failure tracking and banning tools such as fail2ban to neutralise brute-force attempts in real time. Enforce strong, unique credentials across all internet-exposed services and disable default administrative accounts. Maintain comprehensive logging of authentication events for this and similar suspect sources, keep all systems current with security patches, and deploy intrusion-detection systems to identify exploitation patterns early. Regular consultation of IP reputation databases and threat-feeds helps maintain proactive blocking of known malicious infrastructure.

More threatening than 95% of monitored IPs

Threat Categories

Hacking 30

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Reputable Network

This IP is hosted on a network (ASN 51396) with generally good reputation. The ISP Pfcloud UG maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 24% Low Confidence

Confidence History

30. Mar 2026 - 9. Aug 2026
24% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%

Technical Details

Basic Information

IP Address
176.65.148.95
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class B

Geolocation

Country
NL NL
ASN
AS51396
ISP
Pfcloud UG

DNS Information

Reverse DNS
176.65.148.95.ptr.pfcloud.network
PTR Record
Yes
Connection Type
Dynamic

Statistics

Total Reports
195
First Reported
5 Oct 2025
Last Reported
9 Aug 2026, 08:02

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS51396
Pfcloud UG (haftungsbeschrankt)
NL NL

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

429
Total IPs Monitored
82,554
Total Reports
192.4
Reports per IP

Network Context

This IP address belongs to Pfcloud UG (haftungsbeschrankt) (AS51396), which manages 429 IP addresses in our monitoring system. Out of these, 82,554 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

95 %

Global Threat Ranking

This IP is more threatening than 95% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 806,794 reported IPs worldwide

Threat Level 10/10 avg: 6.3 ++
Total Reports 195 avg: 9 ++

Network Comparison

Compared against 595 IPs in ASN 51396

Threat Level 10/10 network avg: 8.9 =
Total Reports 195 network avg: 246 -
Network Pfcloud UG has overall threat level 3/10

Geographic Comparison

Compared against 17,477 IPs in NL

Threat Level 10/10 country avg: 6.3 ++
Total Reports 195 country avg: 30 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

733,697 threat incidents tracked globally • Last 24h: 28,509 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    143,335 19.5%
  2. 02
    BR
    Brazil BR
    110,766 15.1%
  3. 03
    IN
    India IN
    82,129 11.2%
  4. 04
    CN
    China CN
    44,774 6.1%
  5. 05
    SC
    SC SC
    29,233 4%
  6. 06
    DE
    Germany DE
    17,494 2.4%
  7. 07
    NL
    Netherlands NL THIS IP
    17,477 2.4%
  8. 08
    PK
    Pakistan PK
    16,649 2.3%
  9. 09
    AR
    Argentina AR
    16,190 2.2%
  10. 10
    CO
    Colombia CO
    15,135 2.1%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9.4/10 Avg Threat
89% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

20 Related IPs
9.5/10 Avg Threat
77% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "176.65.148.95",
    "threat_level": 10,
    "confidence_score": 24,
    "total_reports": 195,
    "country_code": "NL",
    "isp_name": "Pfcloud UG",
    "asn": "51396",
    "first_reported": "2025-10-05 06:22:27",
    "last_reported": "2026-08-09 08:02:43",
    "exported_at": "2026-10-01T03:45:18+02:00",
    "source": "https://reportedip.com/ip/176.65.148.95/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.