Elevated Risk
IP 195.184.76.175 presents a high-risk threat profile with a threat level of 8/10 and an activity frequency rated 8/10, indicating sustained, repeated malicious behavior. Operating from a United States address within AS213412, a network allocated to ONYPHE SAS, this IP has accumulated 165 total abuse reports from 20 separate automated honeypot sensors over a reporting window spanning September 2025 through June 2026. The overwhelming majority of these reports — 19 out of 20 recent categorized incidents — classify the activity as hacking, with a single email spam report, making unauthorized intrusion attempts the dominant threat vector associated with this address.
The detection data reveals persistent scanning and exploitation activity, consistent with automated honeypot sensor logging of connection attempts and attempted unauthorized access. With 165 total reports and an 89% confidence score, the abuse corpus demonstrates strong evidentiary consensus across multiple independent sensor sources. The network operator ONYPHE SAS, while a legitimate cybersecurity data aggregator, hosts or routes traffic from this address that has generated significant community concern. The nine-month reporting window with consistent monthly detections indicates this is not an isolated incident but rather an established pattern of malicious operation.
Hacking activity in this context encompasses intrusion attempts, vulnerability probing, and unauthorized access operations that exploit exposed services. An IP with this threat reputation poses concrete risk to any exposed SSH, RDP, web application, or database services, particularly those with default credentials, unpatched software, or misconfigured authentication. The attack patterns noted — general attack connections and SMTP spam abuse — suggest this address participates in multiple coordinated campaigns rather than a single intrusion type. Attackers leveraging such infrastructure typically conduct reconnaissance before launching targeted exploitation or credential-based attacks against vulnerable systems.
Site operators should implement immediate defensive measures: block or rate-limit traffic from this IP at the firewall level, enforce strong multi-factor authentication on all remote access services, and ensure all exposed applications run current security patches. Deploying intrusion detection systems and configuring fail2ban or equivalent tools to automatically ban repeat offenders provides automated protection against the connection patterns observed. Regular audit of authentication logs for brute-force signatures and implementation of strict SPF, DKIM, and DMARC email policies will further reduce exposure to the SMTP abuse vectors this address has demonstrated.