Substantial Risk
IP 77.91.71.91 is a high-risk address originating from Georgia that has been extensively documented conducting port-scanning reconnaissance against exposed network infrastructure, with a threat level of 8/10 and a confidence score of 91% based on over 1000 aggregated abuse reports.
The address resolves to network AS211486, operated by Alferov Aleksey Aleksandrovich, and was first flagged in July 2026 with sustained activity continuing through August 2026. Automated honeypot sensors recorded 20 recent reports specifically documenting port-scan activity, with detection logs identifying Cisco ASA device probing patterns. The activity frequency rating of 8/10 indicates consistent, deliberate scanning behavior rather than incidental traffic, suggesting organized reconnaissance efforts targeting exposed network perimeters.
Port scanning represents a critical initial phase in the attack lifecycle, systematically mapping open services and accessible entry points on victim systems. The specific Cisco ASA probing pattern detected indicates intentional reconnaissance of firewall and security appliance configurations, as these devices often serve as primary network boundaries. Successful identification of misconfigured or vulnerable Cisco ASA installations could enable subsequent unauthorized access, data exfiltration or lateral movement within compromised networks. The volume and consistency of reports suggest this IP operates as part of an active scanning campaign rather than isolated probing.
Network defenders should immediately block IP 77.91.71.91 at the firewall level and implement strict ingress filtering policies. Deploying tools such as fail2ban to automatically ban repeat scanning sources reduces manual response burden. Organizations running Cisco ASA devices should verify access control lists, disable unused services, and enable logging for anomaly detection. Continuous monitoring of scanning patterns and correlation with internal asset inventories helps identify exposed services before adversaries can exploit them.