Critical Threat
IP 176.65.149.220 is a critical-risk address linked to sustained, high-volume hacking activity that has generated 5,398 abuse reports from automated honeypot sensors over approximately one year, with the most recent activity recorded in July 2026. Operating from the Netherlands through network provider Pfcloud UG (ASN AS51396), this IP carries a threat level of 10/10 and an activity frequency rating of 8/10, indicating an aggressive, persistent threat actor rather than opportunistic scanning. The sheer volume of reports combined with an 85% confidence score positions this address among the most actively malicious currently observed in community threat feeds.
The detection profile for 176.65.149.220 reflects coordinated intrusion activity captured across 20 separate automated honeypot sensors, with Suricata rules specifically flagging SSH sessions established on non-standard ports. The sustained reporting window from August 2025 through July 2026 demonstrates deliberate, repeated targeting of external services over an extended period. The Netherlands-based hosting infrastructure and ASN assignment to Pfcloud UG suggest this address is likely part of a commercial threat operation or compromised infrastructure used for systematic network penetration testing.
The dominant hacking activity, particularly SSH-related connections on unusual ports, indicates the operator is actively probing for misconfigured servers, conducting credential stuffing or brute-force attacks, or scanning for vulnerable SSH implementations. With 5,398 recorded interactions, this represents a methodical campaign against exposed services rather than random noise. The targeting of non-standard SSH ports specifically suggests evasion techniques designed to bypass basic monitoring or legacy security controls that only inspect port 22 traffic. This pattern poses a concrete risk to any externally facing SSH service, particularly those using default configurations or weak authentication mechanisms.
Network defenders should immediately block 176.65.149.220 at the firewall level and implement automated dynamic blocking using tools such as fail2ban to respond to repeated intrusion attempts. SSH services should be hardened by enforcing key-based authentication, disabling password-based logins entirely, and ensuring strong credential policies. Moving SSH to a non-standard port reduces exposure to automated scanning, though this should complement rather than replace stronger controls. Regular monitoring of authentication logs for patterns associated with this address and routine auditing of exposed services will further reduce the attack surface available to this threat actor.