Critical Alert
IP 195.184.76.141 is a critical-risk address associated with sustained hacking activity, presenting a severe threat level of 10/10 based on 166 total abuse reports and 20 recent hacking-category incidents detected over approximately eleven months of observation.
The address, registered to ONYPHE SAS under autonomous system AS213412 in the United States, was first flagged in August 2025 with continued activity through June 2026, indicating a deliberate and persistent campaign rather than opportunistic scanning. The 89% confidence score reflects high reliability in attributing this behavior to the specific address. Automated honeypot sensors captured 20 recent hacking-related reports, representing the dominant threat category, with the total report volume of 166 underlining the sustained nature of the observed activity. An activity frequency score of 5/10 suggests persistent engagement with targeted systems rather than sporadic connection attempts, consistent with systematic intrusion reconnaissance and exploitation probing.
The dominant hacking classification encompasses a range of unauthorized access attempts, vulnerability exploitation, and intrusion activities that pose concrete risks to any exposed service. An address exhibiting this behavior is actively seeking entry points into networks, whether through exploiting unpatched software, brute-forcing weak credentials, or probing for misconfigured services. The sustained eleven-month timeline and consistent report volume suggest an automated or semi-automated campaign rather than manual probing, meaning the attack infrastructure likely continues operating regardless of individual connection success or failure.
Site operators should immediately block this address at the network perimeter firewall and implement deny-by-default ingress filtering. Deploying fail2ban or equivalent log-based intrusion prevention tools can automatically detect and block repeated connection patterns associated with this activity. Enforcing strong authentication policies, including key-based authentication and account lockout thresholds, significantly reduces the effectiveness of credential-based attacks. Continuous monitoring of authentication logs for source IP 195.184.76.141 and similar abuse-listed addresses is strongly recommended to identify any attempted reconnections.