Critical Threat
IP 91.230.168.162 is a maximum-threat address with a threat level of 10/10 that has generated 162 abuse reports, indicating sustained and aggressive intrusion activity. This IP presents a critical IP reputation risk, having been detected conducting hacking operations alongside targeted exploitation attempts against IoT and ICS infrastructure.
The address belongs to network AS213412 operated by ONYPHE SAS and was first reported in January 2026 with continued activity through June 2026, representing a six-month sustained campaign. All 162 reports originated from automated honeypot sensors, with the dominant threat category being general hacking activity (20 recent reports) alongside confirmed IoT-targeted operations (1 recent report). A Suricata alert specifically flagged TLS invalid record type anomalies tied to IoT/ICS targeting, and the attack-pattern analysis confirms active connection attempts from this address. With an activity frequency rating of 8/10 and a 92% confidence score, the evidence base is robust and consistent across the detection network.
The hacking activity detected involves intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts against exposed services. When combined with the IoT-targeted component, this suggests the operator is systematically scanning for and attempting to compromise both traditional server infrastructure and weakly secured connected devices such as cameras, routers, and industrial control systems. The TLS anomaly pattern indicates sophisticated techniques designed to blend malicious traffic with legitimate encrypted sessions, making detection by conventional logging more difficult.
Site operators should immediately block IP 91.230.168.162 at the firewall level given its critical threat assessment. Implement strict geolocation-based access controls if US-based traffic is not expected. Deploy or enhance intrusion detection systems to identify the TLS invalid record pattern. For IoT and ICS environments specifically, isolate these devices on dedicated network segments, update all firmware, replace default credentials with strong unique passwords, and disable Universal Plug and Play. Regular review of honeypot and firewall logs will help identify any residual attempted connections from this or related addresses.