Extreme Threat
IP 91.230.168.254 is a critical-risk address with a threat level of 10/10 and a 92% confidence score, linked to 164 reported incidents of hacking activity detected over approximately six months through automated honeypot sensors. The high activity frequency score of 8/10 indicates sustained, repeated engagement with target systems, making this IP a persistent and dangerous threat to any exposed network infrastructure.
The IP is registered to ONYPHE SAS operating autonomous system AS213412 and geographically located in the United States. All 164 abuse reports originated from automated honeypot sensors, with the most recent 20 reports consistently categorizing the activity as general hacking attempts. First reported in December 2025, this address continued generating reports through June 2026, demonstrating a sustained campaign spanning roughly six months of active engagement with target systems. The combination of high report volume and elevated activity frequency suggests automated tooling rather than opportunistic manual probing.
The hacking classification encompasses various intrusion attempts, vulnerability exploitation, and unauthorized access activities. Such activity could include scanning for exposed services, attempting to exploit known vulnerabilities, or probing for misconfigured systems. When an IP maintains this level of persistent scanning and exploitation activity across multiple targets, it signals a deliberate, methodical approach to identifying and breaching vulnerable services. The consistent volume of reports over six months indicates this is not random noise but an organized effort to compromise systems at scale.
Network operators should block IP 91.230.168.254 at the firewall level and implement automated blocking through tools such as fail2ban to prevent repeated connection attempts. Systems should be audited for the latest security patches, with particular attention to services commonly targeted by intrusion tools. Intrusion detection systems should be configured to alert on and log all connection attempts from this address for forensic analysis. Proactive blocking based on this IP reputation data is strongly recommended before any successful exploitation occurs.