Extreme Threat
IP 91.196.152.39 is a critical-risk address originating from France that has been definitively linked to sustained hacking activity, with automated honeypot sensors recording 160 incident reports over approximately ten months of continuous operation. This IP presents the highest possible threat classification, reflecting the severity and frequency of its malicious behavior against exposed network infrastructure.
The address is associated with autonomous system AS213412 operated by ONYPHE SAS, a French network entity, and all 160 documented incidents trace exclusively to automated honeypot detections without any community-submitted reports. The eight-month observation window spanning August 2025 through May 2026 reveals an activity frequency rating of eight out of ten, indicating persistent rather than opportunistic intrusion attempts. Each reported incident falls under the hacking category, encompassing general intrusion attempts, vulnerability exploitation and unauthorized access vectors. The 95 percent confidence score substantiates the reliability of these detections, leaving minimal ambiguity about the hostile nature of this traffic.
The sustained volume and frequency of hacking activity detected from 91.196.152.39 signals a systematic campaign rather than casual scanning. Such behavior typically precedes credential compromise, data exfiltration or lateral movement within compromised networks. Organizations exposing services to this source face elevated risk of successful exploitation if patches are delayed or authentication controls remain weak. The exclusive reliance on honeypot sensors for detection suggests this IP actively probes public-facing systems while avoiding direct interaction with documented incident databases, which may indicate sophisticated operational practices designed to evade conventional blacklist tracking.
Network defenders should immediately block or rate-limit traffic originating from this source at the firewall level and monitor logs for any associated authentication attempts against production services. Deploying automated blocking tools such as fail2ban or equivalent intrusion prevention solutions can dynamically respond to repeated hacking attempts without manual intervention. Ensuring all exposed services run current security patches, enforcing strong multi-factor authentication and implementing strict access control policies will substantially reduce vulnerability to the intrusion techniques associated with this address. Continuous monitoring of IP reputation feeds will help maintain updated defensive posture against similar threats.