Significant Threat
IP 77.91.71.23 is a high-risk address originating from Georgia that has generated 1000 abuse reports since July 2026, with port-scanning activity identified as the dominant threat category at a threat level of 8/10 and 91% confidence. The volume of reports combined with an activity frequency rating of 8/10 indicates sustained, deliberate reconnaissance behavior rather than opportunistic or transient scanning.
Automated honeypot sensors filed all 20 of the most recent threat reports attributed to this IP, detecting Ciscoasa-specific port scan and probe activity over a concentrated July-to-August 2026 window. The address is registered to individual operator Alferov Aleksey Aleksandrovich under ASN AS211486, a context that suggests limited legitimate business use for an address exhibiting such aggressive network probing patterns. The discrepancy between 1000 total historical reports and the recent concentrated burst of activity points to either repeated scanning campaigns or multi-stage reconnaissance that has been logged across distributed detection infrastructure.
Port scanning constitutes early-stage reconnaissance: an attacker uses automated tools to probe target systems for open ports and services, building a map of potential entry points before launching exploitation attempts. When this scanning specifically targets Ciscoasa devices, it signals interest in network edge appliances, which often serve as VPN endpoints, firewall gateways, or remote-access portals. Compromising such a device can grant an attacker lateral access to an entire internal network or provide a persistent foothold through VPN credential theft or firmware exploitation. The 91% confidence score indicates strong consensus among detection systems that this behavior is intentional and malicious rather than misconfiguration or benign traffic.
Site operators should block or rate-limit this IP at the network edge using firewall rules, and should audit Ciscoasa deployments for unnecessary exposed services or outdated firmware. Implementing intrusion-detection signatures that flag scanning patterns from single sources can surface similar reconnaissance attempts early. Hardening authentication on all remote-access services, enforcing strong credentials, and deploying tools such as fail2ban to detect brute-force patterns will reduce the viability of any subsequent attacks. Continuous monitoring of honeypot and community abuse feeds helps maintain an up-to-date blocklist for addresses demonstrating sustained hostile activity like that observed from 77.91.71.23.