Extreme Threat
IP 195.184.76.240 is a critical-risk address associated with sustained hacking activity, presenting a severe threat to any exposed network services. With a threat level of 10 out of 10 and 156 total abuse reports submitted through automated honeypot sensors, this IP demonstrates persistent, high-frequency malicious behavior that demands immediate defensive attention.
Analysis of available intelligence reveals that 195.184.76.240, operating under AS213412 with network operator ONYPHE SAS, generated all 156 reports via automated honeypot sensors. The IP was first reported in September 2025 and most recently in June 2026, spanning approximately nine months of documented hostile activity. The activity frequency score of 8 out of 10 indicates continuous rather than sporadic engagement, while the 88 percent confidence score confirms reliable attribution of the observed behavior. The dominant threat category across recent reports is Hacking, accounting for 20 recorded incidents and encompassing various intrusion attempts, vulnerability exploitation, and unauthorized access vectors.
The sustained hacking activity linked to this IP poses significant real-world risk to exposed services. Attackers using this infrastructure systematically probe for vulnerable entry points, attempting to exploit unpatched systems and weak authentication configurations. The persistent nature of the activity, evidenced by the nine-month reporting window and high activity frequency, suggests an automated or semi-automated campaign rather than opportunistic scanning. Organizations running exposed services such as remote administration interfaces, web applications, or authentication portals face the greatest risk of compromise through credential guessing, exploitation of known vulnerabilities, or brute-force attacks orchestrated via this address.
Site operators should treat 195.184.76.240 as a confirmed hostile source and implement immediate blocking at the network perimeter. Deploying or enhancing fail2ban rules or equivalent intrusion prevention tools can automatically ban addresses generating excessive authentication failures. Rate-limiting login attempts, enforcing strong multi-factor authentication on all remote access channels, and maintaining rigorous patch management cycles significantly reduce the attack surface. Continuous monitoring of abuse feeds and maintaining up-to-date firewall deny-lists ensures that this and similar threat actors remain blocked before they can establish persistent access.