Severe Risk
IP 176.65.149.55 is a critical-risk address associated with sustained, high-volume hacking activity, accumulating 4,049 abuse reports across 20 automated honeypot sensors between August 2025 and June 2026. Operating from the Netherlands through AS51396 (Pfcloud UG), this IP demonstrates an 8/10 activity frequency and warrants immediate blocking by any exposed network.
The volume and consistency of reports on this address are exceptional for a single source. Detection data shows repeated connections originating from this address attempting to establish SSH sessions on non-standard ports, a technique frequently employed to evade basic network monitoring. With a 90% confidence score and a 10/10 threat level, analysts can have substantial assurance that this traffic represents intentional malicious probing rather than misconfiguration or benign scanning. The 10-month reporting window spanning August 2025 through June 2026 indicates persistent, automated scanning behaviour rather than a transient incident.
SSH connections on unusual ports typically indicate reconnaissance or lateral-movement attempts targeting exposed services. Attackers use this method to bypass firewall rules that only whitelist standard SSH port 22, potentially seeking entry into systems where default configurations have been altered without corresponding security hardening. The repeated nature of connections from this IP suggests automated tooling conducting systematic enumeration across many targets simultaneously. For any organisation running accessible SSH services, even on non-standard ports, this pattern represents a concrete and ongoing exploitation risk.
Operators should block 176.65.149.55 at the network perimeter immediately. Implementing fail2ban or similar dynamic firewall rules can automatically ban repeat offenders. All SSH services should require key-based authentication, enforce strong password policies, and consider restricting login to known IP ranges via allow-listing. Continuous monitoring of authentication logs for originating IPs matching this address will help identify any successful compromise attempts.