Elevated Risk
IP 195.184.76.130, registered to ONYPHE SAS under ASN AS213412 in the United States, presents a high-risk threat profile with a threat level of 8 out of 10 and a confidence score of 94 percent. This address has accumulated 159 total abuse reports from automated honeypot sensors since January 2026, with activity last observed in June 2026, indicating sustained hostile behavior over approximately six months. The combination of high report volume, elevated activity frequency, and consistent detection across multiple sensor sources establishes a credible and dangerous actor operating from this IP address.
The detection data reveals that IP 195.184.76.130 has been flagged 20 times specifically for general hacking activity, which encompasses intrusion attempts, vulnerability exploitation, and unauthorized access probes. All 20 recent reports originated from automated honeypot sensors, suggesting systematic automated scanning or exploitation attempts rather than isolated incidents. The sustained timeline from early 2026 through mid-2026 demonstrates persistent targeting behavior, and the high activity frequency rating of 8 out of 10 confirms that this IP engages in frequent connection attempts against exposed services. The strong 94 percent confidence score indicates that the classification of this address as malicious is highly reliable based on the accumulated evidence.
Hacking activity represents a broad but serious category of cyber threats involving attempts to gain unauthorized access to systems, exploit software vulnerabilities, or compromise network infrastructure. Attackers operating from addresses like 195.184.76.130 typically scan for exposed services such as remote administration interfaces, web applications, or databases, then attempt to leverage known vulnerabilities or brute-force weak credentials. The real-world risk includes data breaches, system compromise, malware deployment, and pivot attacks against internal networks. Organizations with exposed attack surfaces face direct threats from this IP's sustained probing activities.
Site operators should implement immediate defensive measures including blocking IP 195.184.76.130 at the firewall level to terminate all connection attempts. Deploying or configuring fail2ban or similar dynamic blocklist tools can automate this process and provide ongoing protection against repeated intrusion attempts. Enforcing strong authentication on all accessible services, implementing rate-limiting to throttle rapid connection patterns, and maintaining comprehensive logging for security monitoring are essential complementary controls. Regular patch management and vulnerability scanning of internet-facing systems will reduce the attack surface available to this and similar hostile addresses.