Critical Alert
IP address 91.196.152.126 is a maximum-risk address with a threat level of 10 out of 10 that has generated 158 total abuse reports, predominantly documenting sustained hacking activity including intrusion attempts and exploitation attempts against exposed services. With a confidence score of 91% and an activity frequency rated 8 out of 10, this IP represents a clear and ongoing danger to any accessible network endpoint.
The address is registered in France and operates within AS213412, managed by network operator ONYPHE SAS. Automated honeypot sensors first reported suspicious activity originating from this IP in August 2025, with the most recent reports logged in June 2026 — representing approximately 11 months of continuous hostile activity. Community and sensor reports indicate the dominant threat category is hacking, accounting for all 20 of the most recent documented incidents. Sensor data specifically flagged anomalous TLS protocol behavior, including malformed record types consistent with reconnaissance probes or exploit delivery attempts.
The hacking classification encompasses a broad spectrum of intrusion techniques, including unauthorized access attempts and exploitation of vulnerable services. The detected malformed TLS records suggest the attacking host is probing target systems using non-standard protocol constructs, a common technique employed to evade basic detection or trigger vulnerabilities in misconfigured TLS implementations. For any organization running exposed services, such probing activity frequently precedes more targeted exploitation campaigns aimed at gaining persistent unauthorized access.
Site operators should implement immediate blocking of this address at the network perimeter firewall, ideally using automated dynamic tools such as fail2ban to respond to repeated suspicious connection attempts. Enforcing strict TLS/SSL compliance on exposed services and rejecting anomalous record types will close the specific attack vector observed. Maintaining current patch cycles and deploying intrusion detection monitoring will further reduce exposure to the exploitation techniques this IP has demonstrated.