Elevated Risk
IP 91.230.168.2 is a critical-risk address that has generated 173 confirmed abuse reports across 20 automated honeypot sensors from September 2025 through June 2026, with a threat level of 10/10 and activity frequency rated 8/10; the dominant threat pattern involves sustained hacking activity alongside targeted IoT and ICS reconnaissance.
The report volume for this address is significant, with 173 total reports and a 90% confidence score indicating reliable, substantiated threat intelligence rather than anomalous noise. All detections originated from 20 automated honeypot sensors, confirming that the activity represents sustained, multi-vector hostile reconnaissance rather than isolated scanning events. The nine-month reporting window between September 2025 and June 2026 demonstrates persistent engagement with target infrastructure. Network routing through AS213412 operated by ONYPHE SAS places this IP within a commercial network environment, while geolocation data associates the address with the United States; however, the actual origin of automated attack traffic cannot be definitively confirmed through IP geolocation alone.
The observed attack patterns include connection-based intrusion attempts and deliberate IoT/ICS targeting, suggesting either a coordinated campaign by a single threat actor or multiple actors leveraging shared infrastructure. The hacking activity represents ongoing attempts to exploit vulnerabilities and achieve unauthorized system access, while the IoT-targeted component reflects focused scanning for weakly secured connected devices such as cameras, routers, and industrial control systems. The primary real-world risk is the cumulative exposure created by persistent, varied attack attempts: each exposed service without hardening represents a potential entry point, and the combination of broad intrusion probes with specialized IoT reconnaissance significantly increases the probability of successful compromise for any unprotected target.
Site operators should immediately block this IP at the network perimeter if no legitimate business relationship exists. Implementing rate-limiting on exposed services such as SSH, Telnet, and web interfaces reduces the effectiveness of automated credential attacks. IoT and ICS devices should be isolated on dedicated network segments, their firmware kept current, and default credentials replaced with strong alternatives. Tools such as fail2ban can automate blocking of repeated connection attempts. Organizations should file a detailed abuse report with the network operator AS213412 including supporting honeypot evidence, and should monitor for new attack patterns as threat intelligence evolves.