Extreme Threat
IP address 91.230.168.186 is a high-risk address associated with sustained hacking activity, with automated honeypot sensors recording 156 incident reports between January and June 2026. The IP demonstrates a threat level of 8 out of 10 and carries a confidence score of 92%, indicating a reliable assessment that this address is involved in systematic intrusion attempts. With an activity frequency rated at 6 out of 10, this is not an isolated incident but rather persistent scanning behaviour targeting vulnerable services across multiple deployments.
The evidence base for this assessment derives from 20 independent automated honeypot sensors that logged recent hacking-related activity, contributing to a total of 156 cumulative reports spanning six months. The IP is registered to the United States and operates within AS213412, a network allocation belonging to ONYPHE SAS. While ONYPHE is a recognized cybersecurity data aggregation platform, this particular address has been flagged for connection attempts consistent with unauthorized probing and vulnerability scanning rather than legitimate reconnaissance. The detection window from January 2026 through June 2026 reflects ongoing, sustained engagement rather than transient or opportunistic behaviour.
Hacking activity in this context refers to systematic attempts to exploit vulnerabilities, gain unauthorized access, or probe services for weaknesses. The scale of reporting and consistent activity frequency suggest this IP is part of an automated scanning campaign or botnet-driven operation that catalogues exposed entry points across the internet. For organizations running publicly accessible services such as remote administration interfaces, web servers, or database endpoints, such scanning creates a concrete risk of eventual compromise if vulnerable configurations remain unaddressed.
Network defenders should treat this IP as a confirmed threat source and implement immediate blocking at the firewall or network edge. Deploying tools such as fail2ban or equivalent rate-limiting solutions can automate the detection and rejection of repeated connection attempts from this address. Organizations should audit externally facing services for outdated software and ensure all systems are patched against known vulnerabilities that scanning activity commonly targets. Continuous monitoring of authentication logs for unusual patterns originating from this IP range will help identify any successful reconnaissance before it escalates to a breach.