Extreme Threat
IP address 91.230.168.11 represents a critical-risk threat vector with a maximum threat level rating, sustained over an eight-month active period documented through 165 independent abuse reports. The address is linked to persistent connection-based hacking activity, with automated honeypot sensors consistently detecting unauthorized access attempts originating from this source since November 2025.
The evidence base for this assessment demonstrates severe and consistent malicious engagement. With a threat level of 10/10 and an activity frequency of 8/10, this IP exhibits sustained hostile behavior spanning from November 2025 through June 2026, indicating deliberate rather than opportunistic targeting. The 90% confidence score provides strong statistical reliability for the threat classification. The address is registered to ONYPHE SAS under autonomous system AS213412, routing through United States infrastructure, and has accumulated 20 dedicated hacking-category reports from automated honeypot sensors. The volume and consistency of these reports significantly exceed typical background scanning noise, pointing to systematic threat delivery from a stable network source.
The dominant hacking activity consists of repeated connection attempts designed to establish unauthorized access or probe target systems for vulnerabilities. These systematic connection-based intrusion vectors represent reconnaissance and exploitation attempts against exposed services, potentially targeting authentication interfaces, misconfigured daemons, or known software vulnerabilities. The high activity frequency indicates automated tooling performing persistent network enumeration and exploitation probing. While individual connection attempts may appear routine, the cumulative pattern demonstrates persistent scanning infrastructure seeking initial foothold establishment within target environments.
Organizations should immediately block this address at network perimeter boundaries to eliminate the threat vector entirely. Implementing fail2ban or equivalent rate-limiting solutions effectively neutralizes automated scanning campaigns by temporarily or permanently banning repeat offenders. Enforcing strong authentication mechanisms including multi-factor authentication substantially reduces credential-based attack success rates. Regular security monitoring of authentication logs for brute-force indicators and ensuring prompt patching cycles for exposed services closes common exploitation pathways that this threat category typically targets.