Extreme Threat
IP address 195.184.76.205 is a maximum-threat-level hostile address that automated honeypot sensors flagged 164 times over approximately ten months between August 2025 and June 2026, representing sustained, high-frequency intrusion activity originating from a US-based Autonomous System operated by ONYPHE SAS. With a threat level of 10 out of 10 and a confidence score of 90 percent, this IP presents an unambiguous danger to any exposed network service and warrants immediate blocking at the perimeter level.
The volume and consistency of reports paint a clear picture of persistent automated attack behavior. The 164 total abuse reports generated across 20 distinct automated honeypot sensors over a ten-month observation window indicate that this address is not a transient or opportunistic source but rather a consistently active scanning and exploitation platform. An activity frequency rating of 8 out of 10 confirms the regularity of its hostile connections. The geographic origin in the United States and the AS213412 Autonomous System operated by ONYPHE SAS provide network-level context, though threat actors frequently route traffic through compromised infrastructure in legitimate networks to obscure their origin.
The dominant reported threat category is Hacking, encompassing general intrusion attempts, vulnerability exploitation, and unauthorized access campaigns. This classification covers a broad spectrum of attack patterns, including automated exploitation of known software vulnerabilities, credential guessing, and probing for misconfigured or unpatched services. The concrete real-world risk is that exposed SSH, RDP, web applications, or other internet-facing services associated with this IP face repeated automated intrusion attempts that could eventually succeed against poorly hardened targets, leading to data breach, malware deployment, or network compromise.
Network defenders should treat 195.184.76.205 as definitively hostile and block the address at the firewall or intrusion prevention system level without deliberation. Implement rate-limiting on authentication endpoints to blunt brute-force attempts, enforce strong password policies and key-based authentication where feasible, and maintain timely patching cycles to eliminate known vulnerabilities that automated exploit tools target. Deploying defensive tools such as fail2ban or equivalent log-analysis blocking daemons can automatically respond to this IP's repeated hostile connection patterns. Continuous monitoring of access logs for connections originating from this address will help identify any successful compromise attempts that slip through initial defenses.