Severe Risk
IP 91.230.168.7 presents a critical threat level with a perfect 10/10 rating, representing one of the most dangerous addresses currently active in public threat intelligence feeds. Operating from AS213412 under network operator ONYPHE SAS in the United States, this IP has accumulated 165 total abuse reports with an activity frequency rated 8/10, indicating sustained, high-volume malicious behavior over approximately seven months of continuous reporting.
Detection data shows 165 total reports generated through 20 automated honeypot sensors between December 2025 and June 2026, establishing a persistent threat presence across a significant observation window. The 91% confidence score indicates high reliability in attributing malicious activity to this specific address. With hacking activity representing the dominant reported threat category and accounting for a substantial portion of recent reports, the evidence consistently points to systematic intrusion attempts rather than opportunistic scanning.
Hacking activity encompasses unauthorized access attempts, exploitation of vulnerabilities, and intrusion attempts against exposed services. The sustained reporting pattern spanning multiple months indicates persistent threat actors maintaining infrastructure for ongoing operations, posing concrete risk to any exposed service accepting connections from this address. Organizations with remote administration interfaces, authentication portals, or vulnerable network services should treat any inbound connection from 91.230.168.7 as definitively malicious.
Network defenders should implement immediate blocking of 91.230.168.7 at the perimeter firewall level and monitor for related activity from adjacent address space within AS213412. Deploying automated defensive tools such as fail2ban can dynamically ban repeated connection attempts from abusive sources. Ensuring all exposed services run current security patches, enforcing strong authentication requirements, and implementing rate-limiting on login interfaces will substantially reduce vulnerability to the intrusion activity this address has demonstrated capability for.