Severe Risk
IP 195.184.76.140 is a maximum-threat-level address associated with 194 reported incidents of hacking activity, representing a severe and ongoing risk to exposed network services. With a threat score of 10 out of 10 and an activity frequency rating of 8 out of 10, this IP has demonstrated persistent hostile behavior over a nine-month period from September 2025 through June 2026. The 88 percent confidence score indicates high reliability in attributing malicious activity to this specific source.
Detection data gathered from 20 automated honeypot sensors confirms that IP 195.184.76.140 has repeatedly attempted unauthorized access and connection exploits against monitored targets. The AS213412 autonomous system, operated by ONYPHE SAS, routes this address, which originates from United States infrastructure despite its European network operator. Analysis of sanitized honeypot event logs reveals consistent patterns of attack connection attempts, with hacking representing the dominant reported threat category across all recent incident reports.
The hacking activity attributed to this IP encompasses general intrusion attempts, exploitation probes, and unauthorized access campaigns targeting vulnerable services. For any organization running exposed SSH, RDP, web interfaces, or other network-accessible services, an address with this threat profile poses concrete risk of credential compromise, data exfiltration, or secondary exploitation of compromised systems. The volume and persistence of reports suggest an automated or semi-automated attack campaign rather than opportunistic probing.
Organizations should block IP 195.184.76.140 at the firewall or network edge immediately. Implementing automated blocking tools such as fail2ban or equivalent rate-limiting solutions will prevent repeated connection attempts. Enforcing strong authentication, disabling password-based authentication where possible, and maintaining current patch cycles for all exposed services will reduce vulnerability to the intrusion techniques this address employs. Continuous monitoring of authentication logs for source addresses matching this pattern is strongly recommended.