Maximum Danger
IP 195.184.76.70 is a critical-risk address associated with sustained hacking activity, having accumulated 170 abuse reports with a maximum threat level score of 10/10 and a 90% confidence rating that the activity is malicious. The IP is registered to ONYPHE SAS operating under ASN AS213412 in the United States, and automated honeypot sensors have logged consistent intrusion attempts from this address over a period spanning August 2025 through June 2026. The persistent volume of reports combined with the perfect threat score establishes this as a high-confidence, high-severity malicious actor requiring immediate defensive attention.
Detection data indicates that all 20 most recent reports specifically categorize the activity as hacking attempts, with a moderate activity frequency rating of 4 out of 10 suggesting regular rather than continuous engagement. Every report attributed to this IP originated from automated honeypot sensors, which are designed to emulate vulnerable services and log genuine attack signatures without generating false positives. The sustained reporting window of approximately ten months demonstrates persistent reconnaissance and exploitation probing rather than opportunistic or transient scanning behavior.
The dominant threat category of hacking encompasses unauthorized access attempts, vulnerability exploitation, and intrusion operations targeting exposed services. Connection-based attack patterns logged from this address indicate systematic attempts to establish footholds in target systems, potentially leading to data exfiltration, service disruption, or use of compromised infrastructure as a pivot point for further network attacks. Organizations running exposed services, particularly those with weak authentication mechanisms or unpatched software, face concrete risk of successful compromise if this IP is not blocked or mitigated at the network perimeter.
Site operators should block 195.184.76.70 at the firewall or network edge immediately, as blocking at this layer prevents the address from reaching any exposed service. Implementing fail2ban or similar dynamic firewall tools can automate the blocking process when repeated connection attempts match suspicious patterns. Enforcing strong authentication, disabling unnecessary services, and ensuring systems remain patched against known vulnerabilities will reduce the attack surface that this IP is probing. Continuous monitoring of access logs for this address and similar activity from the AS213412 network will help identify additional mitigation needs.