Critical Alert
IP 91.196.152.119 is a high-risk address located in France with an assigned threat level of 10/10, definitively linked to sustained general hacking activity against exposed network services over approximately ten months of observed reporting.
The IP has accumulated 289 total abuse reports with an activity frequency rating of 8/10, indicating persistent and consistent threatening behavior throughout its observed lifespan. Operating under ASN AS213412 with network operator ONYPHE SAS, this French address was first reported in August 2025 and most recently reported in June 2026. All 20 recent threat reports specifically categorize the activity as general hacking attempts, with detection attributed entirely to automated honeypot sensors distributed across the community. The 80% confidence score reflects strong evidentiary linkage to hostile activity, though some minor uncertainty in attribution remains present in the data set.
General hacking activity encompasses automated vulnerability scanning, brute-force authentication attacks, exploitation of known software weaknesses, and repeated unauthorized access attempts targeting exposed services. The elevated report volume combined with high activity frequency suggests systematic, automated attack infrastructure rather than isolated manual probing. Attackers operating with this pattern typically deploy toolkits to identify entry points, test common credential combinations, and exploit unpatched vulnerabilities across SSH, web applications, databases, or administrative interfaces left accessible on public networks.
Organizations with internet-facing services should immediately block this IP at the network perimeter using firewall rules or intrusion prevention systems. Enforcing strong, unique passwords and multi-factor authentication on all exposed services significantly reduces the effectiveness of credential-based attacks. Rate-limiting incoming authentication attempts and deploying tools such as fail2ban can disrupt automated brute-force campaigns. Maintaining current security patches across all systems eliminates known vulnerabilities that this IP likely attempts to exploit.