High Risk
IP 91.230.168.185 is a high-risk address assigned to ONYPHE SAS under autonomous system AS213412, operating from United States infrastructure, with a threat level rating of 8 out of 10 and a confidence score of 92 percent based on 160 total abuse reports submitted between January and June 2026. The dominant threat activity associated with this IP involves general hacking intrusion attempts, including connection probing and malware or exploit delivery, alongside one confirmed report of exploited-host behaviour indicating the address may be running compromise without the operator's knowledge. With an activity frequency rated 8 out of 10, this address demonstrates persistent offensive operations against exposed services worldwide.
Detection data originates from 20 separate automated honeypot sensors and community-driven abuse reporting mechanisms, capturing 19 reports categorised as hacking activity and one report flagging exploited-host status. The six-month reporting window spanning early 2026 suggests sustained malicious operations rather than isolated incident response, while the high confidence score reflects consistent pattern matching across multiple independent detection points. The AS213412 allocation to ONYPHE SAS, a network operator providing scanning and threat-intelligence services, raises contextual ambiguity regarding whether activity originates from the operator's own reconnaissance infrastructure or from threat actors who have co-opted the address space.
The hacking classification for this IP encompasses connection-based intrusion probing and exploit delivery vectors targeting vulnerable services, posing a concrete risk of unauthorized access to poorly secured systems and potential secondary compromise through deployed malware payloads. The single exploited-host report indicates that either the address itself or a downstream system under its influence has been leveraged as an unwitting attack platform, amplifying the risk that defensive blind spots may exist in adjacent network segments. Organizations with exposed services should treat all inbound connection attempts from this address as hostile until proven otherwise.
Site operators are advised to block IP 91.230.168.185 at the firewall or network edge to eliminate hostile traffic, implement fail2ban or equivalent dynamic denial-of-service tooling to auto-ban repeated attack patterns, enforce strong authentication on all exposed services to mitigate credential-guessing vectors, and monitor logs for the specific attack signatures described to identify potential successful intrusions. Proactive provider notification to ONYPHE SAS regarding the abuse volume is also recommended to support upstream mitigation efforts.