Maximum Danger
IP 91.196.152.123 is a critical-risk address originating from France that has been linked to widespread hacking activity, with automated honeypot sensors recording 156 abuse reports since September 2025. Hosted on network AS213412 operated by ONYPHE SAS, this IP presents an imminent threat to any exposed services within its scanning radius.
Evidence from the aggregated reports paints a clear picture of sustained malicious behavior. The 156 total reports accumulated over roughly ten months, with the most recent submissions logged in June 2026, demonstrate persistent rather than transient activity. A confidence score of 88% indicates high certainty that this traffic represents genuine threat activity, while an activity frequency rating of 7 out of 10 confirms regular engagement with target systems. All 20 of the most recent reports consistently categorize the observed behavior as hacking attempts, with no deviation into other threat categories, reinforcing the dominance of this intrusion-focused pattern.
Hacking activity encompasses systematic attempts to gain unauthorized access to systems through exploitation of vulnerabilities, credential attacks, and reconnaissance probing. The sustained report volume over an extended period suggests automated tooling repeatedly targeting exposed attack surfaces rather than one-off opportunistic scans. For any organization running accessible services—particularly SSH, RDP, web interfaces, or database endpoints—this persistent scanning represents a concrete pathway for adversaries seeking initial access. The longer such traffic remains unblocked, the higher the cumulative risk of successful exploitation.
Site operators should immediately block traffic originating from 91.196.152.123 at the network perimeter firewall or via inbound filtering rules. Deploying automated dynamic blocking tools such as fail2ban can help respond to repeated probing patterns without manual intervention. Hardening authentication mechanisms—enforcing strong passwords, implementing multi-factor authentication, and restricting administrative access to known IP ranges—reduces the impact of any successful intrusion attempt. Regular patching of exposed services and continuous monitoring of IP reputation feeds will help maintain defensive posture against this and similar threat sources.