Elevated Risk
IP 91.196.152.223 is a critical-risk address originating from France that has generated 156 abuse reports over approximately nine months of sustained malicious activity, with automated honeypot sensors flagging it primarily for hacking attempts. The IP operates within AS213412, assigned to network operator ONYPHE SAS, and carries a threat level rating of 10 out of 10 based on 90 percent confidence in the collected evidence. This address represents one of the higher-risk digital assets in current threat-intelligence collections due to the volume and consistency of detected intrusion activity.
Community reports and automated honeypot sensors have documented attack patterns from this IP since August 2025, with the most recent confirmed detection occurring in May 2026, indicating persistent activity across a substantial observation window. The 156 total reports were contributed by 20 separate automated honeypot sensors, providing a broad detection footprint that reinforces confidence in the assessed threat level. With an activity frequency rated at 6 out of 10, this address demonstrates regular, repeated engagement with target systems rather than isolated opportunistic scans. The France-based origin and commercial ASN assignment suggest the infrastructure may be compromised or operating as a dedicated attack node within a broader campaign.
The dominant threat category, hacking, encompasses a range of intrusion activities including exploitation attempts against known vulnerabilities, unauthorized access probes, and other techniques designed to compromise target systems. The concrete risk posed by an address flagged for hacking activity lies in the potential for initial access brokerage, data exfiltration, or use as a pivot point within a larger attack chain. Organizations running exposed services, particularly those with outdated patches or misconfigured authentication, face elevated exposure to this threat vector. The sustained nature of reports from this IP suggests it participates in ongoing scanning and exploitation campaigns rather than transient testing.
Site operators should implement layered defensive controls to mitigate risk from addresses exhibiting this activity profile. Deploying intrusion detection systems with threat-intelligence feeds enables automatic blocking or alerting when traffic from known malicious sources is detected. Rate-limiting authentication endpoints and enforcing strong credential policies, potentially supplemented by tools such as fail2ban, reduces the effectiveness of brute-force and credential-stuffing techniques commonly associated with hacking activity. Regularly reviewing access logs for connections originating from this IP and similar addresses allows security teams to identify successful compromise attempts. Keeping systems patched and following security best practices remains the foundational defence against the exploitation techniques this address seeks to deploy.