Maximum Danger
IP 176.65.149.230 is a critical-risk address operated by Pfcloud UG under ASN AS51396 in the Netherlands that has been linked to 5,605 reported hacking incidents with a threat level of 10 out of 10, representing one of the most persistently malicious IP addresses observed in recent threat-intelligence telemetry. The volume of abuse reports filed against this Netherlands-based endpoint ranks it among the highest-risk sources currently tracked in public IP reputation databases, with automated honeypot sensors consistently flagging the address across an eleven-month observation window spanning August 2025 through July 2026.
The raw numbers paint a clear picture of sustained hostile activity: 5,605 total reports generated at an activity frequency rated 8 out of 10, with an 85% confidence score that the observed behaviour is malicious in nature. All 20 most recent reports classify the activity under the hacking category, indicating a consistent intrusion-focused threat rather than opportunistic noise. Detection has been exclusively attributed to automated honeypot sensors distributed across multiple network vantage points, suggesting the address is being used in systematic scanning or exploitation campaigns rather than isolated probing. The network operator Pfcloud UG hosts this endpoint from the Netherlands, a jurisdiction that, like all hosting environments, can serve both legitimate and malicious purposes depending on the tenant's intent.
The dominant threat category—hacking—encompasses intrusion attempts, vulnerability exploitation, and unauthorized access attempts against exposed services. The specific Suricata signature triggered, "ET INFO SSH session in progress on Unusual Port," indicates this IP is actively conducting reconnaissance and potentially establishing command-and-control connections via non-standard SSH ports to evade standard firewall rules and detection signatures. This behaviour suggests the attacker may be running dictionary-based credential stuffing against SSH daemons, deploying malware payloads, or using the SSH protocol as a covert channel to bypass network security controls. Real-world risk includes complete remote compromise of unpatched Linux servers, lateral movement within internal networks, and data exfiltration from any system that accepts credentials or exhibits vulnerabilities targeted by the attacker.