Significant Threat
IP 77.91.71.92 is a high-risk address operating from Georgia that has been flagged in approximately 1,000 reports with a threat level of 8/10, presenting a significant reconnaissance threat to exposed network infrastructure. This IP demonstrated an activity frequency rating of 8/10 and was actively reported between July and August 2026, indicating sustained hostile scanning behavior over a concentrated timeframe. The volume of reports combined with a 91% confidence score establishes a well-corroborated threat profile warranting immediate defensive attention.
Analysis of the reported threat data reveals that the dominant malicious activity attributed to 77.91.71.92 is port scanning behavior, specifically probing for Cisco ASA firewall vulnerabilities and exposed services. All 20 recent reports originated from automated honeypot sensors that detected structured reconnaissance patterns consistent with pre-attack intelligence gathering. The network is registered to Alferov Aleksey Aleksandrovich under ASN AS211486, and the geographic origin in Georgia places this activity within a specific jurisdictional context for network access decisions. The sustained reporting period spanning two consecutive months indicates persistent rather than opportunistic scanning operations.
Port scanning represents the critical initial phase of targeted attacks, where threat actors systematically enumerate open services and potential entry points before launching exploitation attempts. The specific Cisco ASA probe pattern detected suggests this actor is actively seeking unpatched firewall configurations or management interfaces with known vulnerabilities. For organizations running Cisco ASA appliances or any exposed network services, this reconnaissance activity indicates elevated risk of follow-on intrusion attempts if vulnerabilities are identified during scanning. The 1,000 cumulative reports establish this IP as a prolific scanner operating with confidence that excludes coincidental or benign explanations.
Network defenders should implement immediate blocking of 77.91.71.92 at the firewall level given its confirmed hostile reconnaissance activity. Organizations running Cisco ASA devices should verify all management interfaces are isolated from public internet exposure and ensure current firmware patches are applied. Deploying rate-limiting on authentication endpoints and implementing tools such as fail2ban or similar threat-responsive blocking mechanisms will mitigate credential-based attack risks that typically follow port scanning. Continuous monitoring of scanning patterns and maintaining updated blocklists based on community abuse reports provides ongoing protection against this and similar reconnaissance-focused threats.