High Risk
IP 195.184.76.66, allocated to ONYPHE SAS under autonomous system AS213412 and geolocated to the United States, is a high-risk address classified at 8/10 threat level with 90% confidence based on 156 abuse reports submitted between August 2025 and June 2026. The activity frequency rating of 8/10 indicates sustained, repeated engagement with target infrastructure over this eleven-month period, suggesting an organized or automated operation rather than opportunistic scanning. All 20 most recent threat-category reports specifically document hacking activity detected by automated honeypot sensors, establishing a clear and consistent pattern of intrusion-oriented behavior.
The volume of reports—156 total—and the consistently high activity frequency demonstrate that this IP has been persistently targeting systems through hacking methodologies, which in this context refers to unauthorized access attempts, vulnerability probing, and exploitation-oriented connection attempts. The 90% confidence score reflects substantial corroboration across multiple detection points, reducing the likelihood that these signals represent false positives or benign traffic. The network operator, ONYPHE SAS, is a data-collection and security-research entity, which may indicate this IP serves a legitimate reconnaissance function; however, the volume and persistence of reported intrusion activity against diverse targets suggests the address is being flagged appropriately for hostile probing regardless of the operator's stated purpose.
Hacking activity of this nature poses concrete risks to any exposed service. Repeated connection attempts indicate reconnaissance phases where attackers map available ports, services, and potential entry points before launching targeted exploits. Systems running outdated software, weak authentication configurations, or unpatched vulnerabilities face elevated risk of compromise when exposed to sustained hacking probes of this intensity. The sustained engagement over eleven months implies either a systematic scanning campaign or repeated exploitation attempts against vulnerable infrastructure worldwide.
Site operators should treat this IP as a confirmed threat source and block it at the network perimeter firewall or through automated defensive tools such as fail2ban. Rate-limiting incoming connections and enforcing strong authentication requirements—particularly on remote-access services—will reduce exposure to the intrusion attempts this address has demonstrated. Maintaining current patch cycles and deploying intrusion-detection monitoring will help identify any successful compromise attempts that bypass initial blocking measures. Regular review of access logs for connections originating from this address and similar high-volume sources will support ongoing threat-hunting efforts.