High Risk
IP 91.230.168.3 is a high-risk address originating from the United States network AS213412 (operated by ONYPHE SAS) that has accumulated 161 total abuse reports with an 87% confidence score, indicating sustained and largely confirmed malicious activity over approximately nine months of sustained operation.
Automated honeypot sensors and community reporting mechanisms flagged this address with a notably high activity frequency of 8/10, generating reports across 20 distinct detection sources between September 2025 and June 2026. The overwhelming majority of these reports — 19 out of 20 — classified the activity as general hacking intrusion attempts, with one additional port scan report. The detected attack patterns include connection attempts and reconnaissance probes specifically targeting Cisco ASA firewall infrastructure, suggesting systematic reconnaissance against edge security devices.
The dominant threat category of hacking activity on this IP represents unauthorized access attempts, vulnerability exploitation and intrusion vectors directed at exposed services. When combined with the observed Cisco ASA port scan pattern, this indicates a threat actor conducting reconnaissance followed by potential exploitation of firewall vulnerabilities or misconfiguration weaknesses. Real-world risk includes compromised network perimeter devices, unauthorized lateral movement into internal networks and data exfiltration from poorly secured endpoints that accept connections from this source.
Site operators should immediately block this IP at the network perimeter firewall level given its sustained threat history. Implementing fail2ban or equivalent dynamic blocking tools can automate this response. Organizations running Cisco ASA devices should verify current firmware patches, disable unnecessary services and apply strict access control lists. Continuous traffic monitoring for scanning patterns originating from this address range and enforcement of strong authentication requirements for any exposed administrative interfaces will significantly reduce the risk of successful intrusion attempts.