Generally speaking yes, but realistically only if you’re opening your ports to the internet. There are lots of random scanners out there that are attempting to exploit known 0-days etc in all systems. Granted the biggest one is probably ETERNALBLUE, which I think doesn’t go back to 95, but still.
Obviously browsing infected pages on a hypothetically working web browser would also do the trick, but sites like HN are benign. Windows 95 is so old, though, that you’re unlikely to find much web-enabled software that works well outside of enthusiast projects.
If you plugged it into the internet with a public IP, someone would likely gain full remote control of the machine in a matter of seconds to hours.
You might think you’re safe if you only connect to your home internet, since that’s not wide open for anyone to scan. But then your kid/nephew/friend uses your wifi and they have a spyware-filled Doodle Jump game clone on their phone that asks for permission to connect to the local network, and your kid/nephew/friend wants to play the game so of course they click yes, and now that’s scanning your home network, and now your Windows 7 computer is part of a botnet.
The same thing would happen on the coffee shop’s WiFi, the hotel’s wifi, and so on. Unless you never connect to a network of any kind ever, it’s a bad idea.
The reality seems to be that problems stem from the user and what software they use to access the internet more than just being connected. This jives with your comments as you keep mentioning user actions that result in infections.
Is it behind a router? Most routers have stateful firewalls doing a lot of work to keep random connections from passing to the NAT'd devices behind them. All the "infected in under 5 minutes" stories I've seen were machines connected directly to the internet.
Also, are you monitoring inbound/outbound traffic for that machine? It seems like you should at least be seeing attempts to compromise your machine (even if they're not working). Is it using IPv4? If you've got a setup that stops port scans, vulnerability scanners, and internet worms you should share!