Maximum Danger
IP address 91.230.168.238 is a critical-risk address associated with active hacking operations and IoT targeting, having accumulated 158 abuse reports across automated honeypot sensors since January 2026. Operating from the United States within AS213412 (ONYPHE SAS), this IP demonstrates an 8/10 activity frequency and a 10/10 threat level, indicating persistent and aggressive intrusion-oriented behavior. The dominance of hacking-category reports combined with IoT-specific targeting signals makes this address particularly dangerous for networks with exposed services or inadequately secured connected devices.
Community and honeypot sensor data confirm 21 distinct threat-category reports linked to this address, with 20 explicitly categorized as hacking activity and one as IoT-targeted. The detection footprint spans 20 automated honeypot sensors, suggesting the IP systematically probes external network endpoints for vulnerabilities. The activity window from January through June 2026 shows consistent engagement, with no observable lull in hostile traffic during that six-month period. Geolocation places the source within the United States, while the AS213412 autonomous system is registered to ONYPHE SAS, a network operator whose infrastructure may be leveraged by threat actors or itself conducting broad internet scanning. The reported attack patterns include general connection attempts and protocol-detection behavior targeting IoT and industrial control systems.
The hacking activity linked to this IP reflects automated intrusion attempts, vulnerability probing, and unauthorized-access scanning commonly associated with botnets or coordinated campaign infrastructure. The IoT-targeting component elevates risk for operators of smart devices, routers, cameras, or ICS equipment, as these endpoints frequently lack robust security controls and are attractive targets for compromise or incorporation into botnets. The observed Suricata alert pattern involving protocol-only detection in one direction suggests port-scanning or service-fingerprinting behavior designed to map exposed attack surfaces before exploitation. Real-world risk includes credential stuffing against SSH and telnet services, exploitation of known CVEs on IoT firmware, and lateral movement from compromised smart devices into broader network segments.