Critical Alert
IP 91.230.168.145 is a maximum-risk address linked to sustained hacking activity, accumulating 158 separate abuse reports from automated honeypot sensors over a six-month observation window from January to June 2026.
The address is routed through AS213412, operated by ONYPHE SAS, a network entity based in the United States. Automated honeypot sensors generated all 158 reports, yielding a threat level of 10 out of 10 with a 90 percent confidence rating. The activity frequency of 6 out of 10 and the consistent six-month reporting span indicate persistent rather than opportunistic scanning behavior. The geographic attribution to the United States and the French network operator suggests either compromised infrastructure or intentionally hosted scanning services operating from this address.
Hacking activity encompasses unauthorized access attempts, vulnerability exploitation and various intrusion techniques targeting exposed services. For a system with this threat reputation, the concrete risk involves repeated automated attacks attempting to discover and exploit software vulnerabilities, guess authentication credentials or probe for misconfigured services. The high volume of reports suggests the address participates in large-scale scanning campaigns that systematically sweep networks for exploitable entry points, regardless of whether individual attempts succeed.
Network operators should block or severely rate-limit connections from this address at the firewall level and monitor incoming traffic patterns for similar scanning signatures. Implementing fail2ban or equivalent dynamic firewall rules can automatically respond to repeated hostile connection patterns. Ensuring all exposed services run current security patches, enforcing strong authentication requirements and deploying intrusion detection monitoring will reduce the practical impact of any subsequent exploitation attempts from this or similar hostile sources.