Critical Threat
IP 91.196.152.19 is a high-risk address assessed at the maximum threat level of 10 out of 10, with a confidence score of 87% based on 208 total abuse reports spanning from August 2025 to June 2026. The dominant threat category is hacking activity, encompassing various intrusion attempts and exploitation of vulnerabilities targeting exposed services. This French IP address routes through AS213412, operated by ONYPHE SAS, and its high activity frequency of 7 out of 10 indicates persistent, sustained engagement with target systems rather than isolated probing.
The report volume of 208 incidents over approximately 10 months demonstrates a sustained and systematic threat pattern. All 20 most recent reports consistently categorize the activity as hacking, and detection originated exclusively from automated honeypot sensors, indicating that the activity is automated and likely part of coordinated scanning campaigns. The 87% confidence score reflects substantial corroborating evidence linking this IP to deliberate hostile reconnaissance and exploitation attempts against target infrastructure.
Hacking activity represents one of the most serious threat categories, as it encompasses unauthorized access attempts, vulnerability exploitation, and intrusion behaviors that can lead to data breaches, system compromise, or further malicious propagation. The persistent, automated nature of the activity detected from 91.196.152.19 means that any exposed service with weak authentication, unpatched software, or misconfigured network settings represents a potential target. Real-world risk includes credential compromise, malware delivery, lateral movement within networks, and exfiltration of sensitive data from successfully breached systems.
Administrators should immediately block or significantly rate-limit connections originating from 91.196.152.19 at the network perimeter using firewall rules or intrusion prevention systems. All exposed services should be audited for vulnerabilities, and critical patches should be applied without delay. Implementing strong authentication mechanisms, including multi-factor authentication and account lockout policies, substantially reduces the effectiveness of intrusion attempts. Deploying monitoring solutions capable of detecting scanning patterns and anomalous authentication behavior, combined with tools such as fail2ban to automatically block repeated hostile connection attempts, provides layered defense against this category of threat.