Extreme Threat
IP 91.196.152.113 is a critical-risk address originating from France that has been actively conducting hacking intrusion attempts against exposed network services, accumulating 162 abuse reports with a 93% confidence rating over approximately 11 months of observed malicious activity.
The IP 91.196.152.113 is registered to ONYPHE SAS operating autonomous system AS213412, and all 162 recorded incidents were detected exclusively through automated honeypot sensors with no community-sourced reports contributing to the dataset. The sustained 8/10 activity frequency combined with a maximum threat score of 10/10 indicates persistent, high-intensity scanning and exploitation activity rather than opportunistic or isolated probes. The detection span from August 2025 through June 2026 demonstrates that this address has maintained its hostile operational pattern continuously for nearly a year, suggesting either dedicated infrastructure or a compromised endpoint being leveraged for sustained intrusion campaigns.
The dominant threat category logged against IP 91.196.152.113 is general hacking activity, which encompasses unauthorized access attempts, vulnerability exploitation and intrusion attempts against exposed services. This pattern of behavior poses a concrete risk to any publicly accessible SSH, Telnet, RDP or web-facing application interfaces, as the address has demonstrated consistent intent to compromise systems rather than merely scanning for open ports. Organizations running outdated or misconfigured services face elevated exposure, as automated exploitation toolkits frequently pair initial access attempts with known vulnerability chains.
Network defenders should immediately block IP 91.196.152.113 at the firewall or network edge layer and implement fail2ban or similar dynamic deny-listing tools to automatically block repeated connection attempts from this address. Enforcing strong authentication policies, disabling unused services, applying security patches promptly and deploying intrusion detection monitoring on exposed entry points will substantially reduce the attack surface this hostile actor targets.