Critical Alert
IP 91.230.168.16 is a high-risk address linked to sustained hacking activity, having generated 161 abuse reports from automated honeypot sensors since November 2025 at an intensity rated 8 out of 10. Operating from the ONYPHE SAS network (autonomous system AS213412) in the United States, this IP presents a significant threat to any exposed services due to the volume and consistency of malicious connection attempts recorded over an eight-month observation window.
The dataset underpinning this assessment carries a 90 percent confidence score, reflecting reliable detection by multiple honeypot sensors that consistently flagged connection attempts originating from this address. The 161 total reports, spanning from November 2025 through June 2026, represent an average of roughly 20 monthly incidents, indicating persistent and automated hostile activity rather than isolated scanning. The network operator, ONYPHE SAS, maintains this address on US infrastructure, placing the source within a jurisdiction that may complicate takedown efforts for international abuse referrals.
The dominant threat classification for IP 91.230.168.16 is hacking activity, which encompasses unauthorized access attempts, exploitation of vulnerable services, and intrusion-enabling behaviors such as credential probing and vulnerability scanning. This pattern poses a concrete risk to exposed services including remote administration interfaces, authentication portals, and unpatched network daemons. Each successful or semi-successful attempt could grant an adversary initial access for data exfiltration, lateral movement, or further compromise of connected systems.
Network defenders encountering traffic from this address should implement immediate countermeasures. Blocking or rate-limiting connections from 91.230.168.16 at the firewall or intrusion prevention level is the most direct response. Deploying automated authentication hardening tools such as fail2ban can mitigate brute-force and credential-stuffing attempts associated with this activity. All exposed services should be audited for patches and secure configuration, with particular attention to remote access pathways. Finally, security teams should enrich logs with threat intelligence to correlate any anomalous authentication events against this IP's known attack patterns for faster incident triage.