Severe Risk
IP 91.230.168.184 presents a critical threat with a 10/10 threat level, supported by 163 total abuse reports across automated honeypot sensors and a 91% confidence score. The address is associated with persistent hacking activity originating from the United States via network operator ONYPHE SAS (ASN AS213412). With an activity frequency rating of 8/10 and consistent reporting spanning January through June 2026, this IP demonstrates ongoing, aggressive intrusion behavior that warrants immediate blocking by exposed services.
Detection data shows that all 20 most recent reports specifically categorize the activity as hacking attempts, with the same volume of automated honeypot sensors flagging the address across a six-month window. The sustained reporting period indicates this is not an isolated incident but rather persistent scanning and exploitation attempts against internet-facing systems. The combination of high report volume, consistent detection frequency, and the specific categorization as unauthorized access attempts establishes this as a reliable malicious actor in network telemetry.
Hacking activity encompasses vulnerability exploitation, brute-force authentication attacks, and unauthorized access attempts against exposed services. An IP with this threat profile likely targets weak SSH, RDP, or web application entry points with automated tooling to compromise systems or establish persistent footholds. The real-world risk includes data breach exposure, malware deployment, lateral movement within networks, and resource hijacking. Any internet-facing service accessible to 91.230.168.184 faces active reconnaissance and exploitation pressure.
Site operators should implement immediate blocking of this IP at the firewall or network edge to eliminate hostile access. Deploying authentication hardening measures such as fail2ban, enforcing strong credential policies, and disabling default or administrative accounts reduces attack surface significantly. Continuous monitoring with intrusion detection systems will surface any successful breach attempts. Regular security audits and patch management for internet-facing services close the vulnerabilities this actor targets.