Extreme Threat
IP 91.230.168.76 is a critical-risk address with a perfect threat level of 10/10, linked to 156 total abuse reports and a dominant pattern of hacking activity detected across automated honeypot sensors over a six-month observation window from January to June 2026.
The 156 reports attributed to this IP demonstrate sustained malicious behavior, with an activity frequency rating of 8/10 indicating consistent engagement in hostile operations. All 20 of the most recent reported threat categories specifically reference hacking attempts, encompassing various intrusion techniques, vulnerability exploitation, and unauthorized access vectors. The IP is geolocated in the United States and operates through autonomous system AS213412 under network operator ONYPHE SAS. With a confidence score of 92%, the detection systems maintain high reliability in attributing these activities to this specific address.
Hacking activity represents the most severe category of malicious internet behavior, involving deliberate attempts to compromise system integrity, extract sensitive data, or establish persistent access within target infrastructure. This IP's sustained engagement in such operations across multiple detection points suggests systematic scanning and exploitation efforts rather than opportunistic or accidental contact, posing concrete risks to any exposed network service.
Site operators should treat this IP as a confirmed threat source and implement immediate defensive controls. Deploy network-level blocking or strict rate-limiting for connections originating from this address, enforce strong authentication on all exposed services with key-based authentication and multi-factor verification where possible, maintain rigorous patch management to eliminate known vulnerabilities, and configure intrusion detection systems such as fail2ban to generate alerts and automatically respond to the observed attack patterns associated with this address.