Elevated Risk
IP 91.196.152.24 is a critical-risk address assessed at 10 out of 10, linked to 183 independent incident reports documenting sustained hacking activity against exposed network services. With an 87% confidence score and an activity frequency rated 8 out of 10, this French-hosted IP has demonstrated persistent, high-volume intrusion behavior spanning approximately eleven months, making its reputation extremely poor across threat-intelligence platforms and abuse databases.
Detection data attributed to automated honeypot sensors confirms that all 20 most recent threat-category reports consistently flag hacking activity originating from this address. The reports span from August 2025 through June 2026, indicating continuous operation over an extended period rather than isolated or opportunistic scanning. Geolocation places the host in France, and network routing through ASN AS213412 (operated by ONYPHE SAS) provides the autonomous-system context. The combination of high report volume, elevated activity frequency, and consistent threat categorization across multiple detection points yields the strong 87% confidence assessment that this IP is operating as an active threat actor rather than misclassified legitimate traffic.
The dominant threat classification of hacking encompasses a broad spectrum of intrusion techniques, including port scanning, vulnerability probing, exploitation attempts, and unauthorized access campaigns. The abstract attack-pattern data indicating connection-based activity suggests the address is actively targeting exposed services such as SSH, Telnet, or web interfaces with credential-brute-forcing or exploit payloads. For any organisation running exposed services, this pattern of activity represents a concrete risk of unauthorised system access, data exfiltration, or host compromise through exploited vulnerabilities.
Site operators should immediately review authentication and access logs for any matching connection attempts from this address and consider implementing permanent or time-based blocks at the network perimeter firewall. Hardening authentication on exposed services remains critical: deploying tools such as fail2ban, enforcing certificate-based authentication where feasible, and eliminating password-only access to SSH and administrative interfaces substantially reduces the effectiveness of brute-force attempts. Regular vulnerability scanning and timely patching of exposed services closes known exploitation pathways. Finally, monitoring honeypot and firewall telemetry for continued activity from this IP will help determine whether adaptive blocking or additional honeypot deployment is warranted.