High Risk
IP 91.231.89.114 is a high-risk address linked to sustained hacking activity, originating from French network infrastructure operated by ONYPHE SAS, with 167 automated honeypot reports logged over approximately ten months and a threat level of 8/10 indicating significant malicious intent.
The IP address 91.231.89.114, registered to AS213412 under French network operator ONYPHE SAS, has generated 167 confirmed abuse reports from automated honeypot sensors since its first logged detection in August 2025, with the most recent activity recorded in June 2026. The confidence score of 89 percent and activity frequency rating of 8/10 reflect a consistent pattern of hostile engagement observed across the detection period. All 20 of the most recent reports categorically attribute the observed behavior to hacking activity, encompassing various intrusion attempts and unauthorized access vectors. The concentration of reports within automated honeypot infrastructure suggests this address is actively scanning and probing public-facing services at scale, with the extended operational window indicating persistent rather than opportunistic threat behavior.
Hacking activity, as classified by the reporting sensors, encompasses unauthorized access attempts, vulnerability exploitation, and intrusion vector testing against exposed services. The concrete real-world risk posed by an address exhibiting such behavior includes the potential for compromise of unpatched systems, brute-force attacks against authentication portals, and reconnaissance activity that precedes more targeted exploitation. The sustained frequency of reports indicates this address is engaged in systematic rather than incidental probing, raising the probability that it will eventually successfully exploit any vulnerable service it encounters.
Network operators and security administrators should consider implementing automated blocking mechanisms such as fail2ban to dynamically ban addresses demonstrating repeated connection attempts indicative of scanning or brute-force activity. Exposed services should enforce strong authentication policies, including multi-factor authentication where feasible, and rate-limiting on login interfaces to mitigate credential-based attacks. Maintaining comprehensive patch management schedules for all internet-facing systems reduces the attack surface available to exploitation attempts. Continuous monitoring of abuse report feeds and correlation of source addresses against existing blocklists enables proactive defensive posture adjustments before successful compromises occur.