Critical Threat
IP 195.184.76.163 is a critical-risk address operated by ONYPHE SAS under ASN AS213412 that presents a severe threat to internet-facing infrastructure, with 164 abuse reports filed against it by automated honeypot sensors and a threat level rating of 10 out of 10. The IP is geolocated to the United States and has been actively engaged in hostile operations between August 2025 and June 2026, with an activity frequency score of 8 out of 10 indicating persistent, high-volume malicious behavior over an approximately eleven-month period.
The detection data reveals that the overwhelming majority of recent hostile activity attributed to 195.184.76.163 falls under the hacking category, accounting for 19 of the 20 recorded threat reports, while a single port-scan event was also documented. These reports were generated across 20 separate automated honeypot sensors, yielding a 93 percent confidence score that the observed behavior is genuinely malicious rather than false positive noise. The sustained volume of reports over an extended timeframe, combined with the diversity of honeypot sensors detecting the activity, paints a consistent picture of an IP engaged in systematic intrusion attempts against target systems.
The dominant hacking activity associated with this address includes unauthorized access attempts and exploitation-oriented operations targeting exposed services, while the documented CiscoASA port scan behavior specifically probes for vulnerabilities in Cisco adaptive security appliances. Port scanning of this nature serves as reconnaissance for subsequent targeted attacks, identifying which services are running and potentially vulnerable. The presence of both direct intrusion attempts and port-scanning reconnaissance in the same threat profile indicates that operators of 195.184.76.163 are conducting thorough pre-attack information gathering followed by active exploitation attempts.
Administrators with internet-facing systems should immediately block or heavily rate-limit traffic originating from 195.184.76.163 at the network perimeter firewall level. Deploying or strengthening fail2ban rules or equivalent dynamic blocking tools can automate this response. All exposed services, particularly Cisco security appliances and any administrative interfaces, should be verified as fully patched and monitored for authentication anomalies. Reducing the attack surface by eliminating unnecessary open ports and implementing strict firewall rules that reject unsanctioned inbound connections will substantially diminish the effectiveness of reconnaissance operations from this source.