Extreme Threat
IP 91.230.168.176 is a critical-risk address associated with sustained hacking activity, including active SSH intrusion attempts, and has accumulated 162 abuse reports from automated honeypot sensors since January 2026.
The IP is registered in the United States and routed through AS213412, operated by ONYPHE SAS, with a 91% confidence score across 20 recent hacking-category reports. Detection sensors captured both direct attack connections and Suricata alerts flagging SSH sessions established on non-standard ports, indicating deliberate attempts to establish persistent access rather than simple reconnaissance. The activity frequency of 7/10 and consistent monthly reporting between January and June 2026 confirms this is an automated, sustained campaign rather than isolated probing.
The dominant threat category involves unauthorized access attempts targeting SSH services. These intrusions exploit weak or default credentials and unpatched authentication mechanisms to gain entry into Linux servers and network appliances. Once established, an attacker can escalate privileges, deploy malware, harvest credentials or use the compromised host as a pivot point for further network penetration. For organizations exposing SSH to the internet, this represents a direct pathway to full infrastructure compromise.
Defensive measures should include immediate ingress filtering or blocking at the network perimeter for this address. Operators should enforce key-based authentication and disable password authentication entirely on exposed SSH daemons, while implementing rate-limiting tools such as fail2ban to throttle repeated connection attempts. Regular audits of authentication logs, automated alerting on anomalous session behaviour and prompt patching of SSH daemon vulnerabilities will further reduce exposure to this class of threat.