High Risk
IP 195.184.76.92 is a high-risk address with a threat level of 8 out of 10 that has been linked to sustained hacking activity detected by automated honeypot sensors. This US-based IP, operated by ONYPHE SAS under ASN AS213412, has generated 334 total abuse reports with an activity frequency rated 8 out of 10, indicating persistent and repeated hostile engagement against targeted systems.
Analysis of the available data shows that 20 recent reports specifically categorized the threat as hacking activity, with detection occurring across 20 separate honeypot sensors. The timeline spans from October 2025 through June 2026, representing approximately eight months of continuous hostile activity. The detection signatures included connection attempts and Suricata alerts flagging protocol mismatches in both communication directions, suggesting the IP is probing for misconfigured services or attempting to exploit service confusion vulnerabilities. With a confidence score of 77 percent, there is substantial evidentiary basis for treating this address as a genuine threat source rather than a mischaracterized legitimate actor.
Hacking activity encompasses a broad range of intrusion attempts, vulnerability exploitation, and unauthorized access vectors. Protocol mismatch attacks often indicate systematic reconnaissance where threat actors test how different services respond to unconventional or malformed protocol sequences. This behavior frequently precedes more targeted exploitation attempts against specific vulnerabilities identified during the probing phase. The sustained frequency and volume of reports suggest an automated or semi-automated campaign rather than opportunistic scanning, increasing the likelihood that systems exposed to this IP face credential stuffing, brute force, or exploitation attempts.
Organizations should implement immediate defensive measures including blocking or rate-limiting traffic from this IP at the network perimeter, deploying authentication hardening such as certificate-based authentication or multi-factor authentication for exposed services, and monitoring logs for connection patterns matching the observed protocol mismatch signatures. Security teams may also consider implementing automated threat response tools such as fail2ban to dynamically update firewall rules based on observed attack patterns. Regular review of honeypot telemetry and abuse report feeds will help maintain updated threat intelligence for this and similar hostile addresses.