Extreme Threat
IP address 91.196.152.216 is a critical-risk endpoint associated with widespread hacking activity, registered in France under ASN AS213412 and operated by ONYPHE SAS, with a threat level rating of 10 out of 10 based on 196 total abuse reports sourced from 20 automated honeypot sensors. The dominant threat category driving this IP's poor reputation is general hacking activity, encompassing intrusion attempts, vulnerability exploitation and unauthorized access campaigns targeting exposed services across the internet. Activity frequency scored at 6 out of 10 indicates sustained, repeated offensive operations rather than isolated probing, placing any exposed infrastructure in immediate danger of compromise if adequate defensive controls are not deployed.
Analysis of the report corpus reveals this address has been actively flagged by honeypot sensors over an approximately 11-month observation window spanning August 2025 through June 2026, demonstrating persistent malicious intent rather than opportunistic scanning. The concentration of 20 distinct detection sources confirms that this IP engages in broad, indiscriminate targeting across multiple sensor networks, a pattern consistent with automated attack toolkits or compromised host activity. The 84 percent confidence score provides substantial reliability that the observed behavior accurately reflects genuine malicious engagement rather than misclassification or false positive noise. Geographic and network attribution to France places this actor within European infrastructure, though the presence of exploited-host classification suggests the underlying machine may itself be a compromised asset unknowingly participating in the attack chain.
The hacking activity attributed to 91.196.152.216 represents a concrete threat to any exposed service accepting inbound connections, particularly those with weak authentication mechanisms, unpatched software or misconfigured access controls. Attackers deploying such IP addresses typically run automated exploit scripts designed to identify and compromise vulnerable targets at scale, leveraging the element of volume to find the rare unprotected system. The abstract attack patterns noted—attack connections and malware or exploit activity—align with credential stuffing, brute-force authentication attacks and delivery of malicious payloads designed to establish persistent footholds within target networks. Organizations exposing services to this IP risk data exfiltration, lateral movement and integration into broader botnet operations without rapid intervention.