Critical Threat
IP address 91.196.152.22 represents a critical threat with a maximum threat level of 10 out of 10 and a 90% confidence score, making it one of the most definitively malicious addresses currently active. This French IP has accumulated 169 separate abuse reports from automated honeypot sensors over approximately seven months of continuous activity, with an exceptionally high activity frequency rating of 8 out of 10. The address is associated with network operator ONYPHE SAS operating under ASN AS213412, and its sustained, high-volume hostile behavior warrants immediate defensive action from any organization with exposed services.
Detection data shows the address was first reported in December 2025 and remained active through June 2026, indicating persistent rather than opportunistic scanning behavior. All 169 reports originated from automated honeypot sensors, with the dominant threat category classified as general hacking activity encompassing intrusion attempts, vulnerability exploitation and unauthorized access probes. The sheer volume of reports combined with the extended operational window and high activity frequency demonstrates a deliberate, systematic campaign rather than incidental reconnaissance traffic, and the 90% confidence score confirms these are genuine hostile connections with minimal false-positive risk.
Hacking activity as detected represents the broadest category of cyber threat, encompassing any attempt to breach, compromise or gain unauthorized control over exposed network services. For organizations running publicly accessible SSH, FTP, HTTP or other network services, an address conducting persistent hacking probes poses a direct risk of credential compromise, service exploitation or initial access broker activity that could precede more sophisticated attacks. The sustained intensity of 169 reports over seven months indicates this IP is unlikely to be casual scanning and may be part of coordinated infrastructure used repeatedly for targeted or opportunistic intrusions.
Site operators should treat IP address 91.196.152.22 as definitively hostile and implement immediate blocking at the network perimeter firewall or intrusion prevention system level. Deploying fail2ban or equivalent log-based authentication hardening tools on any exposed services will automatically ban repeated connection attempts from this address. Enforcing strong, unique credentials and disabling password-based authentication in favor of key-based access dramatically reduces the effectiveness of any brute-force or credential-stuffing attempts originating from this source. Continuous monitoring of authentication logs for any future connections from this IP, even after blocking, provides valuable early warning if the address is repurposed or spoofed in subsequent attack waves.