Notable Threat
IP address 195.184.76.162 represents a high-risk threat actor with a threat level of 8 out of 10, assessed with 87 percent confidence based on 182 total abuse reports submitted through automated honeypot sensors. The address is associated with the AS213412 autonomous system operated by ONYPHE SAS and originates from address space allocated to the United States. The dominant threat category is general hacking activity, which encompasses intrusion attempts, vulnerability exploitation, and unauthorized access attempts against exposed services. With an activity frequency rated 8 out of 10 and a detection span running from October 2025 through June 2026, this IP has demonstrated sustained, repeated offensive behaviour over an extended window, indicating a persistent automated scanning or exploitation campaign rather than an isolated incident.
The evidence base consists entirely of automated honeypot detections, totalling 182 reports across 20 distinct sensor sources, which gives the dataset a high degree of corroboration across multiple observation points. The consistent volume of reports over approximately nine months suggests this is not a short-lived opportunistic scan but rather part of an ongoing, methodical operation. The AS213412 ASN, while operated by ONYPHE SAS — a company known for internet scanning and OSINT tooling — does not imply that the activity attributed to addresses within this allocation is sanctioned or performed by the operator itself, as any autonomous system may carry traffic from diverse sources including compromised infrastructure or routed through bulletproof hosting arrangements. The geographic classification to the United States reflects the IP allocation registry data, though the physical origin of the attacking traffic may differ from the registered location.
General hacking activity as a threat category is broad by design, capturing any attempt to gain unauthorized access, probe for vulnerabilities, or move laterally within a target environment. Common manifestations include credential stuffing, exploitation of unpatched services, brute-force authentication attacks, and reconnaissance sweeps to identify open ports or misconfigured daemons. For a site operator with an exposed SSH, RDP, web application, or database service, an IP exhibiting this behaviour poses a concrete risk of account compromise, data exfiltration, or foothold establishment within the network. The sustained frequency rating of 8 out of 10 indicates the address is actively and repeatedly targeting systems rather than passively scanning, raising the urgency of defensive action.