Critical Threat
IP 195.184.76.33 represents a critical cybersecurity threat, scoring a maximum 10 out of 10 on threat severity with a 90% confidence rating based on 169 abuse reports from automated honeypot sensors. The address is linked to active hacking activity including general intrusion attempts and unauthorized access campaigns, with an exceptionally high activity frequency of 8 out of 10 indicating persistent offensive operations over an eight-month observation window from October 2025 through June 2026.
The threat intelligence compiled against this address draws exclusively from 20 distinct automated honeypot sensors that captured repeated connection attempts and attack patterns consistent with exploitation reconnaissance. With 169 total reports concentrated across this detection network, the volume signals deliberate, systematic scanning behaviour rather than opportunistic or random traffic. The target network is AS213412, operated by ONYPHE SAS, a France-registered entity whose United States infrastructure hosts this malicious endpoint. The sustained activity period spanning autumn 2025 into mid-2026 demonstrates persistent threat actor interest in this scanning vector.
Hacking activity as documented here encompasses the broader category of intrusion attempts, vulnerability probing, and unauthorized access exploitation against exposed services. The "attack connection" pattern noted across multiple sensors suggests the address participates in automated exploit delivery or credential-based attack sequences targeting internet-facing systems. For any organization with SSH, Telnet, or similar services directly accessible from the internet, this address poses a concrete risk of compromise through brute-force or exploitation toolkit deployment. The high frequency rating confirms this is not a transient probe but an ongoing campaign.
Network defenders should immediately block 195.184.76.33 at the firewall or edge-device level given its maximum threat classification and confirmed malicious activity. Implementing fail2ban, CrowdSec, or similar dynamic blocklist tools that automatically ingest abuse feeds provides automated protection against repeated offensive source addresses. Organizations should enforce strong authentication on all internet-facing services, deploy intrusion detection systems to flag automated exploitation attempts, and maintain rigorous patch management schedules to limit vulnerability exposure. Continuous monitoring of honeypot and community threat feeds will ensure timely awareness of evolving patterns from this and related hostile infrastructure.