High Risk
IP address 91.230.168.4 presents a high-risk threat profile with a threat level of 8 out of 10, supported by 170 total abuse reports and a 91% confidence score, indicating that automated honeypot sensors and community reporting have consistently flagged this address for malicious activity originating from United States-based infrastructure operated by ONYPHE SAS on ASN AS213412.
Analysis of the reporting data reveals that over approximately nine months between September 2025 and June 2026, this IP accumulated reports across 20 separate automated honeypot sensors, averaging a notably high activity frequency of 7 out of 10. The overwhelming majority of confirmed threat categories consisted of general hacking activity, accounting for 19 distinct reports, while a single port scan report was logged. The detected attack patterns specifically include CiscoASA port scanning and probing activity alongside general attack connections, suggesting this address systematically probes network edge devices as part of its reconnaissance methodology.
The dominant hacking classification encompasses various intrusion attempts, vulnerability exploitation and unauthorized access activities that pose a direct threat to exposed services. When combined with the documented CiscoASA reconnaissance patterns, this indicates the operator behind 91.230.168.4 is conducting structured probing to identify exploitable weaknesses before launching follow-on attacks. The concentration of reports from multiple independent honeypot sensors significantly increases confidence that this activity represents deliberate hostile scanning rather than misconfiguration or benign traffic, and the sustained activity frequency demonstrates persistent rather than opportunistic threat behavior.
Site operators should immediately review firewall rules to block or rate-limit traffic from this address and similar addresses exhibiting comparable scanning behavior. Implementing automated blocking via defensive tools such as fail2ban can proactively deny repeated connection attempts. Exposed CiscoASA and network edge device configurations should be audited to ensure unnecessary services are disabled and vendor-supplied patches are applied promptly. Continuous monitoring of authentication logs for brute-force patterns and enforcement of strong credential policies across remote access services will substantially reduce the attack surface this reconnaissance is designed to exploit.