Critical Threat
IP address 91.230.168.174 is a high-risk threat actor associated with general hacking activity, with 161 total abuse reports logged over a six-month window from January to June 2026. The address carries a threat level of 8 out of 10 and a confidence score of 91 percent, indicating that automated honeypot sensors and community reporting mechanisms have reliably identified this IP as a source of intrusion-related traffic. Its activity frequency is rated 8 out of 10, reflecting sustained rather than sporadic malicious behavior across the reporting period.
The network hosting this IP is AS213412, operated by ONYPHE SAS, a French cybersecurity company whose infrastructure appears to be repurposed or abused for scanning activity originating from a United States vantage point. All 20 recent threat-category reports specifically classify the activity as hacking, which encompasses general intrusion attempts, vulnerability exploitation, and unauthorized access probes. Detection came exclusively from automated honeypot sensors, with each report contributing to a cumulative total of 161 incidents spanning six months. The consistent volume and frequency of reports suggest that IP address 91.230.168.174 is part of an organized scanning or exploitation campaign rather than isolated opportunistic probing.
The hacking classification for this IP indicates that exposed services reachable from the internet are actively being targeted with connection-based intrusion attempts. Such activity typically involves automated tools scanning for known vulnerabilities, misconfigured services, or weak authentication mechanisms to establish unauthorized access. The sustained frequency and high report count suggest the threat actor is systematically probing a wide range of targets, increasing the probability that any unhardened or unpatched service could be compromised if targeted.
Site operators should immediately block IP address 91.230.168.174 at the network perimeter firewall or via inbound access-control lists, and ensure any exposed services are kept current with security patches. Implementing strong authentication requirements, limiting exposure of administrative interfaces to trusted networks, and deploying tools such as fail2ban or equivalent log-analysis utilities can reduce the effectiveness of automated intrusion attempts. Continuous monitoring of authentication logs for repeated failed login patterns from this address will further harden defensive posture.