Extreme Threat
IP 91.230.168.127 is a critical-risk address associated with sustained SSH brute-force and intrusion activity, with 159 abuse reports logged between January and June 2026. Operating from AS213412 under ONYPHE SAS, this IP presents a severe, active threat to any exposed SSH service.
Automated honeypot sensors recorded 20 distinct hacking events from this single source over a six-month observation window, yielding a confidence score of 93% and an activity frequency rating of 8 out of 10. The detection data shows persistent connection attempts consistent with automated credential stuffing and unauthorized access probing. Suricata signatures specifically flagged SSH sessions in progress on expected ports, indicating the attacker successfully established connections before executing further commands. The sustained monthly reports spanning half a year confirm persistent rather than transient malicious behavior from this address.
The dominant attack pattern—SSH session establishment combined with general hacking methodology—indicates this IP participates in credential-based attacks designed to gain unauthorized shell access to targeted systems. A successful breach would grant the attacker a foothold for lateral movement, data exfiltration, or deployment of secondary payloads such as backdoors or cryptominers. The high activity frequency demonstrates deliberate, repeated campaigns against internet-facing services rather than opportunistic scanning. The 93% confidence score leaves minimal ambiguity in the malicious classification.
Site operators should implement immediate blocking or rate-limiting for this address at the network perimeter. Enforce key-based authentication combined with defensive tools such as fail2ban to throttle brute-force attempts. All SSH services should enforce strong password policies, disable root login, and restrict access via firewall rules to known IP ranges where feasible. Continuous monitoring for the observed attack patterns—particularly successful SSH session establishment from this source—will help identify any breach attempts that slip through initial defenses.