Severe Risk
IP 176.65.149.212 is a high-risk address with a 10/10 threat rating that has generated 4,813 abuse reports from automated honeypot sensors, predominantly linked to general hacking activity including unauthorized access attempts and intrusion activity over an eight-month period from December 2025 through July 2026.
Automated honeypot sensors flagged this Netherlands-based IP with an 85% confidence score and an activity frequency rated 8/10, indicating sustained offensive operations. AS51396, operated by Pfcloud UG, has been the source of repeated Suricata alerts detecting SSH sessions on unusual ports — a technique frequently employed to bypass standard security monitoring and evade firewall rules that only allow SSH on default ports.
The dominant threat category, hacking, encompasses various intrusion attempts and exploitation attempts targeting exposed services. Detecting SSH traffic on non-standard ports from this IP suggests active reconnaissance and credential-based attack campaigns are underway, with operators attempting to establish footholds in targeted networks by circumventing conventional port-based filtering rules that assume SSH runs on its default port only.
Site operators should immediately block this IP at the network perimeter firewall, implement fail2ban or equivalent log-based attack mitigation to automatically ban repeated connection attempts, and restrict SSH access to known whitelisted IP ranges wherever possible. Additionally, monitoring for unexpected outbound SSH connections and maintaining strict patch cadence on externally facing services will reduce exposure to the exploitation activity this address is known for conducting.