Maximum Danger
IP 195.184.76.37 is a critical-risk address with a threat level of 10 out of 10, associated with 177 abuse reports and confirmed malicious hacking activity targeting exposed services. With an 87 percent confidence score and six instances of reported activity over a six-month window from January through June 2026, this address presents a severe and persistent risk to any internet-facing infrastructure it encounters. The IP is registered to ONYPHE SAS under autonomous system AS213412, and its geographic location traces to the United States, though the routing and origin of attack traffic often diverge from registration data.
Detection of malicious activity originated from 20 automated honeypot sensors, which recorded sustained interaction with this address across the first half of 2026. The volume of reports and the consistent activity frequency indicate that 195.184.76.37 is not a transient or opportunistic scanner but rather an address engaged in deliberate, repeated intrusion attempts. The network operator, ONYPHE SAS, operates infrastructure that may serve scanning or intelligence-gathering purposes, which complicates attribution. Nonetheless, the pattern of confirmed hostile probes places this IP squarely in the category of addresses requiring immediate defensive action.
The dominant threat category for 195.184.76.37 is general hacking activity, specifically aligned with indicators of unauthorized SSH session establishment on expected service ports. This behavior is consistent with credential-guessing campaigns, brute-force attacks against Secure Shell services, or the establishment of footholds for further network penetration. An address exhibiting such patterns can compromise poorly configured servers, expose internal systems to lateral movement, and facilitate data exfiltration or cryptojacking. The risk extends to any organization running SSH services on standard ports without adequate hardening or monitoring.
Defensive measures should include immediate blocking or rate-limiting of traffic from 195.184.76.37 at the network perimeter firewall, coupled with monitoring for any successful authentication attempts. Administrators should enforce key-based authentication over passwords for SSH access, implement fail2ban or equivalent tools to automatically block repeated login failures, and ensure all SSH services run on non-standard ports where feasible. Regular review of authentication logs and deployment of intrusion detection signatures will further reduce exposure to the intrusion tactics this address employs.