Significant Threat
IP 91.230.168.170, allocated to AS213412 and operated by ONYPHE SAS in the United States, is a high-risk address with a threat level of 8 out of 10 and a confidence score of 92 percent. This IP has accumulated 157 total abuse reports, with automated honeypot sensors flagging it 20 times specifically for hacking activity within the last reporting window spanning January through June 2026. An activity frequency rating of 8 out of 10 indicates sustained, repeated malicious behaviour rather than isolated probe attempts.
Detection data shows consistent hostile engagement from this address over a six-month period, with the full corpus of 20 recent reports attributed exclusively to automated honeypot infrastructure. The IP's association with ONYPHE SAS—a network operator—and its United States routing present a mixed picture regarding attribution, as autonomous system assignments can mask the true origin of abuse traffic. The elevated confidence score of 92 percent provides strong statistical backing for treating these detections as genuine indicators of hostile intent rather than false positives or misclassification.
The dominant threat category, hacking, encompasses a broad spectrum of intrusion attempts including exploitation of software vulnerabilities, brute-force credential attacks, and unauthorized access probes against exposed services. For organisations running publicly accessible SSH, FTP, HTTP, or database services, this type of activity represents a direct pathway to system compromise, data exfiltration, or use of compromised infrastructure for further attacks. The sustained frequency of reports suggests this IP is systematically scanning and attempting exploitation rather than conducting opportunistic one-off probes.
Site operators should implement immediate defensive measures including blocking or rate-limiting traffic from this address at the firewall level and monitoring logs for any matching connection attempts that may indicate successful reconnaissance. Hardening authentication on exposed services is strongly advised—enforcing key-based authentication over passwords, implementing account lockout policies, and deploying tools such as fail2ban to automatically ban repeat offenders after failed login thresholds. Regular patch management and vulnerability scanning will further reduce the attack surface that this IP and others like it attempt to exploit.