Notable Threat
IP 91.196.152.107 is a high-risk address assessed at 8/10 threat level, definitively linked to sustained hacking activity with 242 abuse reports filed over approximately seven months. Operating from France through ASN AS213412 under the network operator ONYPHE SAS, this IP has demonstrated a consistent 8/10 activity frequency, indicating persistent rather than opportunistic behaviour. The confidence score of 80% reflects substantial corroborating evidence from automated honeypot sensors, making this one of the more reliably malicious profiles in recent public telemetry.
Detection data confirms 20 distinct hacking-category incidents attributed to this address, with each report originating exclusively from automated honeypot infrastructure rather than passive community filings. The eight-month activity window between October 2025 and May 2026 reveals persistent engagement with vulnerable services across multiple targets. Network analysis further contextualises this activity within AS213412, a French autonomous system operated by ONYPHE SAS, which may suggest the infrastructure itself could be compromised or operating as a scanning proxy rather than representing a direct threat actor endpoint.
The dominant attack pattern involves protocol-level reconnaissance, specifically detected through a Suricata alert flagging "Applayer Mismatch protocol both directions." This pattern indicates the attacking host is sending traffic that violates expected protocol state machines — a hallmark of vulnerability scanning, service fingerprinting, or payload crafting designed to elicit unexpected responses from target services. Such mismatches often precede more targeted exploitation attempts, as attackers map exposed attack surfaces before selecting appropriate exploit chains. The sustained frequency and volume of these probes suggest an automated scanning campaign rather than manual exploration.
Site operators should immediately block or heavily rate-limit traffic from this address at the firewall or load-balancer level. Implementing fail2ban or equivalent log-analysis tools can automate the detection and temporary banning of repeated connection attempts matching this pattern. Ensuring all internet-facing services run current patched versions eliminates most vulnerabilities these protocol-probing campaigns attempt to exploit. Finally, enabling detailed intrusion-detection logging for protocol anomalies will provide early warning should this or related infrastructure shift tactics.