Maximum Danger
IP 91.230.168.252 is a high-risk address associated with sustained hacking activity, with automated honeypot sensors recording 160 abuse reports over a six-month period from January to June 2026. This US-based IP, operated by ONYPHE SAS under ASN AS213412, demonstrates an activity frequency rating of 8 out of 10, indicating persistent and targeted intrusion attempts against exposed network services.
Analysis of the reported data reveals consistent malicious engagement over approximately six months, with all 160 reports attributed to automated honeypot detection systems. The threat level of 8/10 combined with a 91% confidence score provides substantial evidentiary weight to the classification of this address as a source of hacking activity. The concentration of reports within the hacking category suggests that the operator behind this IP is primarily focused on vulnerability exploitation and unauthorized access attempts rather than a single attack vector.
Hacking activity as documented by honeypot sensors encompasses a broad spectrum of intrusion techniques including exploitation of known vulnerabilities, brute-force authentication attempts, and probing for misconfigured services. The persistent nature of the observed activity from this IP — evidenced by the high report volume and elevated activity frequency — indicates automated tooling rather than opportunistic scanning. Real-world risk includes potential compromise of weakly secured SSH, Telnet, or web-facing applications that may be exposed to the internet.
Organizations with publicly accessible services should implement immediate blocking or rate-limiting for this IP at the network perimeter, enforce strong and unique credentials alongside multi-factor authentication on all exposed entry points, maintain rigorous patching schedules to eliminate known vulnerabilities, and consider deploying defensive automation tools such as fail2ban to detect and mitigate automated attack patterns originating from high-risk sources like this one.