Critical Alert
IP 91.196.152.190 is a maximum-risk address located in France that has been extensively reported for hacking activity, accumulating 178 abuse reports with a 10/10 threat level and an 81% confidence score through automated honeypot sensors between August 2025 and June 2026. This IP reputation data indicates a clear and persistent danger to any exposed network service, with the sustained volume of reports suggesting ongoing automated exploitation attempts rather than isolated incident response testing.
The reporting data for 91.196.152.190 reveals consistent, long-term malicious behavior across a ten-month window. All 20 of the most recent threat reports classify the activity as hacking, with detection sourced exclusively from automated honeypot infrastructure. The address operates within AS213412, administered by ONYPHE SAS, a French network operator. An activity frequency rating of 4/10 indicates regular, recurring attack attempts, while honeypot event logs specifically reference connection attempts and honeypot interactions, suggesting automated vulnerability scanning and exploitation toolkit deployment rather than manual probing.
Hacking activity encompasses a broad spectrum of intrusion methodologies, including vulnerability exploitation, credential-based attacks, and attempts to establish unauthorized system access. This threat classification represents the most severe category in common abuse taxonomies, as it directly implies active attempts to compromise target systems. For organizations running internet-facing services, this address poses an immediate risk of exploitation if any unpatched vulnerabilities or misconfigurations exist in exposed attack surfaces.
Network operators should immediately implement blocking or strict rate-limiting for inbound traffic from 91.196.152.190 at the perimeter firewall level. Deploying dynamic security tools such as fail2ban can automate the response to repeated connection attempts from this source. All exposed services should be kept fully patched according to vendor release cycles, and strong authentication mechanisms including multi-factor authentication should be enforced wherever possible to reduce the impact of any successful intrusion. Continuous monitoring of authentication and access logs for connections originating from this address will provide early warning of exploitation activity.