Maximum Danger
IP 91.230.168.138 is a critical-risk address assessed at 10/10 threat level with 91% confidence, classified as a high-frequency source of hacking activity detected across 157 aggregate abuse reports submitted by automated honeypot sensors over a six-month observation window from January through June 2026.
The IP originates from United States infrastructure operated by ONYPHE SAS under autonomous system AS213412, and its threat reputation has been consistently eroded by sustained malicious engagement logged during the first half of 2026. Automated honeypot sensors recorded connection attempts matching known hacking intrusion patterns, with an activity frequency rating of 8 out of 10 indicating persistent rather than opportunistic behaviour. The 157 total reports represent a substantial volume that surpasses typical background noise levels seen across ThreatPulse's sensor network, and the 91% confidence score reflects strong evidentiary consensus among detection signatures.
Hacking activity in this context encompasses unauthorized access attempts, exploitation probing, and intrusion-oriented connection behaviour directed at exposed network services. For an organisation running publicly accessible SSH, Telnet, or similar management interfaces, this IP represents a concrete threat vector where repeated probing could eventually uncover weak or default credentials. The persistent nature of the activity — evidenced by the activity frequency metric — suggests an automated scanning campaign or a brute-force operation rather than a single reconnaissance probe.
Site operators should block this address at the network perimeter firewall and implement fail2ban or equivalent log-analysis tools to automatically ban repeated connection attempts targeting authentication services. Enforcing key-based authentication, disabling password authentication entirely, and applying rate-limiting rules on exposed services will substantially reduce the practical impact of any continued probing from this source.