Significant Threat
IP 77.91.71.25 is a high-risk address originating from Georgia, associated with sustained port scanning activity against Cisco ASA firewall appliances, generating over 1,000 total abuse reports with a threat level of 8/10 and a confidence score of 91 percent. The scanning behavior was detected consistently across 20 automated honeypot sensors during July and August 2026, indicating persistent reconnaissance operations against exposed network infrastructure.
The report data shows 1,000 total submissions, with the most recent activity categorized as port scan probes specifically targeting Cisco ASA devices. This concentration of reports across a two-month period, combined with an activity frequency rating of 8/10, suggests systematic and repeated scanning rather than opportunistic probes. The network is operated by Alferov Aleksey Aleksandrovich under ASN AS211486, a designation typically associated with smaller hosting or individual network operations rather than large telecommunications providers.
Port scanning represents the initial phase of a network intrusion attempt, where an attacker systematically queries target systems to identify accessible services and potential entry points. When this scanning is specifically directed at Cisco ASA appliances, it indicates the operator is seeking to catalogue exposed management interfaces, VPN endpoints, or vulnerable services running on firewall devices. This reconnaissance data enables subsequent attacks tailored to identified weaknesses, making early detection and blocking critical to network protection.
Network administrators should immediately block this IP at the firewall level and implement geolocation-based restrictions if inbound traffic from Georgia serves no legitimate business purpose. Deploying rate-limiting rules on authentication interfaces, enabling intrusion detection signatures for scanning patterns, and monitoring logs for repeated connection attempts from this address will further harden defenses. Implementing fail2ban or similar dynamic blocking tools can automate the response to repeated port scan behavior, reducing the window of exposure to hostile reconnaissance.