Substantial Risk
IP 195.184.76.93 is a critical-risk address operating from United States infrastructure (ASN AS213412, ONYPHE SAS) that has accumulated 164 abuse reports across automated honeypot sensors between November 2025 and June 2026, with a dominant pattern of hacking activity alongside confirmed exploited-host behaviour indicating this address is actively weaponised for intrusion campaigns.
The volume and consistency of reporting paint a clear picture: 164 total reports from 20 distinct automated honeypot sensors over approximately seven months represents sustained hostile engagement rather than opportunistic scanning, and the 90% confidence score reflects strong corroboration across detection sources. The 8/10 activity frequency score confirms this is not a dormant or reactivated threat but an ongoing operation. Geographic placement in the United States on infrastructure belonging to ONYPHE SAS does not indicate legitimate use — the reported threat categories (19 hacking incidents, 1 exploited host confirmation) and observed attack patterns involving attack connections and malware or exploit activity are consistent with this address functioning as an attack platform.
The dual classification of this IP as both a hacking source and an exploited host reveals the most concerning aspect of its behaviour: the address appears to be actively conducting intrusion attempts while simultaneously showing indicators that it may itself be compromised and co-opted into broader attack infrastructure. The "attack connection" pattern suggests sustained attempts to establish unauthorised sessions against targeted services, while "malware/exploit activity" points to exploitation tool deployment. For any organisation exposing services to this IP's network range, the concrete risk is unauthorised access, credential compromise, or initial access brokerage for follow-on intrusions.
Site operators should block 195.184.76.93 at the network perimeter immediately, implement strict rate-limiting on any inbound authentication endpoints, and enforce strong multi-factor authentication across all privileged access paths. Regular review of authentication logs for source IP 195.184.76.93 or its associated AS213412 range is advised, and tools such as fail2ban can provide automated response against repeated connection attempts. If persistent engagement is observed, consider engaging the hosting provider to report malicious infrastructure.