Critical Alert
IP 91.231.89.116 represents a critical-risk threat, scoring the maximum 10 out of 10 on the severity scale with an 87 percent confidence rating based on 155 abuse reports submitted through automated honeypot sensors. This French IP routed through ASN AS213412 (ONYPHE SAS) has been actively targeting systems under the hacking threat classification over an eleven-month period from August 2025 through June 2026, indicating sustained intrusion and exploitation activity.
Detection data reveals consistent hostile engagement with an activity frequency rating of 6 out of 10, demonstrating persistent rather than opportunistic targeting. The uniform reporting source—all 155 reports generated by automated honeypot sensors—provides methodological consistency that reinforces the high confidence score. Report volume averages roughly fourteen incidents monthly across the observation window, with twenty reports specifically categorized under hacking activity, confirming deliberate and repeated intrusion attempts against target infrastructure.
The hacking classification encompasses unauthorized access attempts, vulnerability exploitation, and intrusion activities targeting exposed services. This threat profile indicates the address has been observed attempting to compromise systems through exploitation of known weaknesses, credential-guessing attacks, or targeting of unpatched software. The sustained nature of activity spanning nearly a year suggests automated tooling conducting persistent intrusion campaigns against vulnerable network endpoints.
Network defenders should immediately block 91.231.89.116 at firewall or network edge devices. Rate-limiting authentication endpoints, particularly administrative interfaces, reduces the effectiveness of credential-guessing campaigns. Deploying intrusion detection rules tuned to exploitation patterns enhances visibility into attempted compromises. Systems should receive current security patches, enforce least-privilege access controls, and monitor for behavioral anomalies matching this threat profile. Dynamic tools such as fail2ban can automatically update blocking rules based on observed authentication failures from this source.