Critical Alert
IP address 195.184.76.200 represents a critical threat with a maximum threat level of 10/10 and a 92% confidence score, based on 157 total abuse reports collected between August 2025 and June 2026. This address has been linked predominantly to general hacking activity, including intrusion attempts, vulnerability exploitation, and unauthorized access attempts against exposed services. The frequency of activity is rated 8/10, indicating persistent and aggressive operational patterns. With 20 separate automated honeypot sensors detecting malicious connection attempts originating from this IP, the evidence base for its malicious classification is robust and well-corroborated across multiple detection points.
The geographic location of 195.184.76.200 is registered to the United States, and the associated network is AS213412 operated by ONYPHE SAS. Detection data indicates that all 157 reported incidents originated from automated honeypot infrastructure, suggesting systematic and automated scanning or attack campaigns rather than isolated manual probing. The eleven-month reporting window from August 2025 through June 2026 demonstrates sustained hostile activity, with the activity frequency score of 8/10 confirming that this IP has maintained a consistently high attack cadence throughout this period. The concentration of 20 recent reports specifically categorized as hacking activity underscores an ongoing interest in exploiting vulnerable services across the internet.
Hacking activity associated with this IP encompasses the broad spectrum of intrusion methodologies, including port scanning, service enumeration, exploitation attempts against known vulnerabilities, and credential-based attacks against exposed entry points. The volume of reports and sustained frequency suggest that 195.184.76.200 is likely running automated toolkits designed to systematically probe networks for weaknesses rather than conducting highly targeted manual operations. Real-world risk includes potential compromise of unpatched systems, brute-force attacks against authentication interfaces, and exploitation of misconfigured services that accept connections from unknown sources. Any exposed service reachable from this IP should be considered a potential target for immediate reconnaissance and follow-on attack.