Substantial Risk
IP 195.184.76.201 is a high-risk address associated with sustained hostile activity, scoring 8/10 in threat level with a notable 155 total abuse reports and a confidence rating of 93 percent. Observed across AS213412 (operated by ONYPHE SAS) and geolocated in the United States, this IP has been flagged by automated honeypot sensors for hacking-related intrusion attempts and targeted port-scanning behavior since August 2025, with continued reporting through June 2026. The volume of reports and high activity frequency indicate a persistent threat rather than opportunistic or transient scanning.
The detection data reveals 155 distinct reports sourced from 20 separate automated honeypot sensors, spanning approximately ten months of activity. Within recent submissions, 19 reports classified the activity as general hacking attempts while one report documented port-scanning reconnaissance. Honeypot sensors captured both attack connection events and CiscoASA-specific port scan probes directed at firewall infrastructure, suggesting the actor is systematically enumerating edge security devices. The consistent report volume across an extended timeframe points to automated, repeated targeting rather than a single probing event.
Port scanning serves as reconnaissance, mapping exposed services and potential entry vectors before launching targeted exploitation. The CiscoASA-specific probe indicates deliberate reconnaissance of firewall and security appliance configurations, which could inform more sophisticated follow-on attacks. General hacking activity encompasses intrusion attempts and exploitation of vulnerabilities on reachable services. Together, these behaviors create a compound risk for any exposed system, as reconnaissance enables more precise and effective exploitation downstream.
Site operators should implement firewall rules to block or significantly rate-limit traffic from this IP and similar addresses in the same network range. Deploying automated blocking tools such as fail2ban can mitigate repeated intrusion attempts without manual intervention. All exposed services should enforce strong, unique credentials and multi-factor authentication to reduce the impact of any successful authentication brute-forcing. Finally, reviewing access logs for patterns consistent with the observed attack connections and port scans will help identify whether any probing has reached internal infrastructure that warrants additional hardening.