Extreme Threat
IP 91.196.152.108 is a critical-risk address originating from France that has generated 176 abuse reports over approximately ten months of sustained malicious activity, with recent reports exclusively documenting hacking intrusion attempts detected by automated honeypot sensors.
Network intelligence identifies this IP as part of AS213412, operated by ONYPHE SAS, a French network entity. The address maintains a threat level score of 10 out of 10 and an activity frequency rating of 7 out of 10, indicating persistent and methodical engagement with target systems. Detection confidence stands at 86 percent across 20 independent automated honeypot sources that filed reports between August 2025 and June 2026. All 20 most recent reports categorize the observed activity under the "Hacking" classification, encompassing various intrusion techniques, vulnerability exploitation attempts, and unauthorized access vectors.
Hacking activity represents a broad spectrum of deliberate intrusion behaviours targeting exposed services, network infrastructure, and applications. This category captures exploitation attempts against known vulnerabilities, credential-based attacks, and reconnaissance probes designed to identify entry points into victim environments. The sustained frequency and persistent nature of activity from this address suggests an automated or semi-automated operation actively scanning and attempting exploitation across multiple targets rather than isolated opportunistic attempts.
Organizations with exposed services should consider implementing defensive measures to mitigate risk from this source. Deploying authentication hardening mechanisms such as multi-factor authentication and strong credential policies significantly reduces successful intrusion probability. Rate limiting and temporary blocking based on source IP behaviour patterns can disrupt automated attack sequences. Implementing comprehensive intrusion detection and prevention systems with up-to-date threat signatures enables real-time identification of exploitation attempts. Regular security patching and vulnerability management remain fundamental to reducing attack surface exposure.