Maximum Danger
IP 91.230.168.75 is a high-risk address associated with sustained hacking activity, generating 156 abuse reports over six months with a 10/10 threat level and 91% confidence score.
The IP is registered to AS213412 under network operator ONYPHE SAS and originates from the United States. Automated honeypot sensors detected the activity consistently between January and June 2026, with the most recent reports in the final month of that window. The volume of reports combined with an activity frequency rating of 7/10 indicates persistent, automated threat behavior rather than isolated scanning probes.
Hacking activity encompasses a broad range of intrusion attempts including exploitation of vulnerabilities, brute-force authentication attacks, and unauthorized access probing against exposed services. The real-world risk posed by an address exhibiting this behavior is direct compromise of unpatched or poorly configured systems, potential data exfiltration, and use of compromised infrastructure as a staging point for further attacks.
Site operators should consider blocking this IP at the firewall level given its confirmed malicious reputation. Implementing automated blocking tools such as fail2ban can provide real-time protection against repeated connection attempts. Exposed services should enforce strong authentication policies, including multi-factor authentication where supported. Maintaining current patch cycles for all internet-facing software eliminates known vulnerabilities commonly exploited in these attacks. Regular review of authentication logs for unusual patterns helps identify compromise attempts early before successful unauthorized access occurs.