Elevated Risk
IP 195.184.76.203, registered to ONYPHE SAS in the United States under ASN AS213412, is a high-risk threat actor with an 8/10 threat level and an 89% confidence score, accumulating 163 total abuse reports from automated honeypot sensors over roughly nine months between September 2025 and June 2026.
The evidence base for this IP is substantial: 20 independent automated honeypot reports document repeated malicious connections, while the sustained activity frequency of 8/10 confirms persistent, ongoing engagement rather than transient scanning. The network operator, ONYPHE SAS, operates this US-registered address as part of AS213412, and detection systems flagged Suricata alerts matching protocol anomalies consistent with malware or exploit activity. The dominant threat classification is general hacking at 20 reports, supplemented by a single exploited host designation, indicating this address may simultaneously operate as an active attacker and as a compromised platform being weaponized by external threat actors without the owner's knowledge.
The dual threat classification carries distinct but complementary risks. The hacking activity signals repeated intrusion attempts, vulnerability probing and unauthorized access scanning against exposed services. Simultaneously, the exploited host flag suggests 195.184.76.203 could itself be a compromised system repurposed as an attack platform, meaning the nominal operator may be an unwitting participant in malicious campaigns. The detected protocol-only communication pattern aligns with covert command-and-control traffic or reconnaissance activity that often precedes exploit delivery, representing a concrete pre-exploitation threat to any reachable target.
Network defenders encountering this IP should implement immediate blocking at perimeter firewalls or intrusion prevention systems, strengthen authentication hardening on exposed services such as SSH using tools like fail2ban, conduct forensic log review for any matching connection attempts to identify potentially compromised internal hosts, and consider notifying ONYPHE SAS through appropriate abuse channels so they can investigate whether their infrastructure has been commandeered.