Maximum Danger
IP 176.65.149.67 is a critical-risk address operating from the Netherlands that has generated 5,239 abuse reports between August 2025 and July 2026, representing one of the most active hacking vectors documented in recent threat-intelligence feeds. With a threat level of 10 out of 10 and an activity frequency rated 8 out of 10, this IP demonstrates persistent, high-volume intrusion activity that warrants immediate blocking by any exposed network perimeter.
The 5,239 total reports received a confidence score of 87%, indicating highly reliable attribution of malicious behaviour. Detection was consistent across 20 independent automated honeypot sensors, confirming the IP's repeated targeting of vulnerable services. Pfcloud UG, operating under ASN AS51396, hosts this address in the Netherlands, a jurisdiction frequently exploited by threat actors for its hosting infrastructure. The sustained reporting window of nearly one year — from August 2025 through July 2026 — underscores that this is not opportunistic scanning but deliberate, repeated intrusion activity.
The dominant reported category is general hacking activity, specifically including reconnaissance and establishment of SSH sessions on non-standard ports. This pattern suggests the actor is probing for exposed SSH daemons running on unusual ports to evade standard firewall rules and default deny-policies. Combined with the volume of reports, this IP poses a concrete risk of unauthorized access, credential compromise and lateral movement across any network segment where SSH on non-standard ports is permitted without strict authentication controls.
Network operators should block 176.65.149.67 at the firewall or edge-router level and monitor logs for any attempted connections from this address. Enforcing key-based SSH authentication, disabling password authentication entirely and relocating SSH to non-standard ports with fail2ban or similar defensive tooling will substantially reduce exposure. Regular audit of permitted inbound connections and prompt patching of any vulnerable services will further harden the attack surface against this category of threat.