Critical Threat
IP address 91.196.152.121, registered to ONYPHE SAS under ASN AS213412 in France, presents a critical threat level of 10/10 based on 173 abuse reports submitted by automated honeypot sensors over approximately ten months between August 2025 and June 2026, with a dominant activity profile centered on hacking and unauthorized intrusion attempts.
The volume and consistency of malicious activity linked to this address are significant: the 173 total reports represent sustained aggressive behavior rather than isolated scanning, and an activity frequency score of 6/10 confirms repeated, deliberate engagement with vulnerable services over an extended timeframe. All 20 most recent threat-category reports classify the activity as Hacking, indicating a concentrated focus on intrusion attempts, vulnerability exploitation and unauthorized access vectors rather than opportunistic noise traffic. Detection originated exclusively from automated honeypot sensors, which are designed to simulate exposed services and capture genuine attack patterns without generating false positives, lending high confidence (90%) to the classification.
The dominant Hacking classification encompasses a broad range of intrusion methodologies including automated exploitation attempts against known vulnerabilities, credential brute-forcing and lateral movement probes directed at exposed network services. Real-world risk materializes when organizations expose SSH, Telnet, HTTP administration panels or other network interfaces to unfiltered inbound traffic from untrusted sources, as this IP has demonstrated clear intent to identify and compromise such entry points. The sustained frequency and confirmed malicious intent make this address a reliable indicator of coordinated hostile reconnaissance and exploitation activity.
Organizations with internet-facing services should block IP address 91.196.152.121 at the network perimeter firewall, implement fail2ban or equivalent dynamic blockade tools to automatically ban repeated intrusion attempts, enforce strong multi-factor authentication on all administrative interfaces and ensure comprehensive logging with alerting for connections originating from this source.