Maximum Danger
IP address 91.230.168.179 is a critical-risk host that automated honeypot sensors and community reports have flagged across multiple detection points, with 165 abuse reports documenting persistent intrusion activity over a six-month window and a threat level of 10 out of 10 indicating severe, confirmed malicious behavior.
Recorded activity spans from January 2026 through June 2026, placing this address within recent observation windows, and the 91% confidence score reflects strong corroboration across the 20 distinct automated honeypot sensors that contributed reports. The IP originates from United States infrastructure under ASN AS213412 operated by ONYPHE SAS, though threat actors frequently route through compromised endpoints or bulletproof hosting to obscure true origin. Of the documented threat categories, Hacking activity dominates with 19 recent reports while a single IoT-targeted event was also recorded, and the attack patterns consistently reference connection attempts and honeypot interaction events. The activity frequency score of 7 out of 10 demonstrates sustained, repeated engagement rather than opportunistic single-pass scanning.
The predominant hacking activity represents active intrusion attempts, vulnerability exploitation, or unauthorized access campaigns targeting exposed services, while the IoT-targeted classification indicates the operator is specifically probing for poorly secured connected devices such as cameras, routers, or smart appliances with default credentials or unpatched firmware. Together these patterns suggest this IP participates in systematic reconnaissance and exploitation operations, potentially building a footprint for subsequent credential theft, botnet recruitment, or lateral movement into downstream targets. Organizations with internet-facing services or unsegmented IoT deployments face the most direct exposure to this address's activity.
Site operators should immediately block or rate-limit connections from this address at the network perimeter, enforce strong multi-factor authentication on all remote access services, and apply current security patches to reduce vulnerability exposure. Implementing defensive tools such as fail2ban or similar connection-throttling mechanisms can automatically mitigate brute-force patterns, and network segmentation isolating IoT devices from core infrastructure limits lateral movement risk if initial probes succeed. Continuous monitoring of authentication logs for sources matching this IP range will help detect any successful breach attempts.