Notable Threat
IP 91.196.152.112 is a high-risk French address assessed at threat level 10/10 that has generated 161 abuse reports from automated honeypot sensors, with its activity overwhelmingly dominated by hacking intrusion attempts targeting connected devices and infrastructure.
Security monitoring systems logged this address across 20 separate automated honeypot sensors over a ten-month observation window spanning August 2025 through June 2026, indicating persistent and systematic scanning behaviour rather than opportunistic contact. The confidence score of 89% reflects strong corroboration across multiple independent detection points, while the activity frequency rating of 8/10 demonstrates consistent engagement with target systems rather than isolated probes. The IP originates from AS213412, operated by ONYPHE SAS, a French network operator whose infrastructure may be hosting scanning services or could itself be compromised and weaponised for external attacks. Of the 20 logged threat categorisations, 19 classified the activity as general hacking intrusion attempts while one specifically flagged IoT-targeted behaviour, suggesting the address participates in campaigns designed to identify and compromise internet-connected devices.
Hacking activity of this intensity typically involves repeated attempts to exploit known vulnerabilities, brute-force authentication credentials, or probe for misconfigured services that grant unauthorized access to systems. The IoT-targeted component indicates this address specifically participates in campaigns designed to discover and compromise poorly secured connected devices such as routers, cameras, and smart appliances that often ship with weak default configurations. The volume of reports and persistent activity pattern suggests this is not random scanning but coordinated reconnaissance or exploitation activity that could precede more serious data breaches or device hijacking for botnet recruitment.
Site operators should immediately block or rate-limit connections from this address at the network perimeter using firewall rules or intrusion prevention systems, and implement authentication hardening measures such as certificate-based authentication, non-default SSH ports, and multi-factor authentication on any exposed management interfaces. Monitoring should be intensified for authentication logs and connection attempts matching the observed "attack connection" patterns, with tools such as fail2ban configured to automatically block repeated offenders. Network segmentation isolating IoT devices from critical infrastructure is strongly recommended, along with ensuring all connected devices run current firmware and employ non-default credentials to reduce vulnerability to the specific threats this address has demonstrated capability for.