Maximum Danger
IP address 91.230.168.250 is a critical-risk address that automated honeypot sensors flagged 168 times over approximately six months, with the majority of recent reports cataloguing it as an active source of hacking activity including malware and exploit behavior. With a threat level of 10 out of 10 and an activity frequency rated 8 out of 10, this IP represents a persistent and high-confidence threat to any exposed service.
Community reports and automated honeypot sensors detected this address operating from AS213412, a network administered by ONYPHE SAS and geolocated to the United States. Detection occurred between December 2025 and June 2026, generating 168 unique abuse reports sourced from approximately 20 distinct automated honeypot sensors. The concentration of reports across multiple independent detection points yields a 90 percent confidence score that this activity is malicious rather than misclassified benign traffic. The sustained reporting window of several months indicates that this address has been consistently active rather than fleeting in its offending behavior.
The dominant threat category for IP 91.230.168.250 is hacking activity, encompassing unauthorized access attempts, exploitation of vulnerabilities, and the deployment of malware against target systems. The secondary categorization as an exploited host suggests this address may itself be a compromised system being weaponized by threat actors without the owner's knowledge, functioning as an unwitting attack platform. The combination of these categories indicates dual risk: the address poses an active threat to internet-facing services while also potentially representing a victimized system whose resources are being abused for malicious purposes.
Network defenders encountering this IP should block or aggressively rate-limit connections originating from 91.230.168.250 at the firewall or intrusion prevention level. Deploying automated dynamic blocking tools such as fail2ban can reduce the manual burden of managing repeated connection attempts. Authentication hardening measures including multi-factor authentication and certificate-based access controls will reduce the impact of any successful intrusion. Organizations should also review inbound connection logs for any indicators matching the reported attack connection and malware activity patterns, and consider notifying the hosting provider to alert the potential system owner that their infrastructure may be compromised and participating in malicious activity.