Maximum Danger
IP 91.230.168.6 is a critical-risk address associated with 180 documented abuse reports and assessed a perfect threat score, indicating an active and persistent threat actor operating from United States infrastructure.
Analysis of the available intelligence reveals this IP was first reported in August 2025 with continued activity through June 2026, demonstrating sustained engagement over approximately ten months. The 20 automated honeypot sensors that captured this activity logged 180 total reports with an activity frequency rated 8 out of 10, suggesting regular rather than sporadic malicious behavior. Network registration records trace this address to AS213412 operated by ONYPHE SAS, a data aggregation firm. The overwhelming majority of recent threat reports (18 of 20 categorized incidents) classify the observed activity as general hacking intrusion attempts, while 2 reports specifically document IoT and ICS-targeted operations. The detected attack patterns included connection attempts and targeted probes against internet-of-things and industrial control systems.
The dominant hacking activity encompasses various intrusion vectors including vulnerability exploitation and unauthorized access attempts against exposed services. Combined with confirmed IoT and ICS targeting, this IP poses a concrete risk to poorly secured connected devices, smart infrastructure, and network edge services that may lack robust authentication or patching cadences. An address with this IP reputation approaching an exposed service represents an active reconnaissance and exploitation risk that could precede credential compromise, data exfiltration, or device compromise.
Network defenders should immediately block or rate-limit this IP at the perimeter firewall, particularly for services reachable from the internet. Implementing intrusion detection rules tuned to connection-pattern anomalies and enforcing strong authentication on all exposed endpoints significantly reduces exploitability. Regularly updating firmware on IoT and ICS devices, segmenting these networks from critical infrastructure, and monitoring for scanning behavior from this address and similar sources provides layered defense against the observed threat profile.