Notable Threat
IP 91.231.89.13 is a high-risk address operating from France that has been linked to 161 reported hacking intrusion attempts, with an 8/10 threat level indicating serious ongoing malicious activity. The IP presents a credible danger to any exposed network services, and its high confidence score of 90% reflects consistent, verified hostile behaviour across automated honeypot detection systems.
Network intelligence places IP 91.231.89.13 within AS213412, operated by ONYPHE SAS, a French entity. The address was first reported in September 2025 and remained active through June 2026, spanning approximately nine months of documented hostile operations. All 161 abuse reports originated from automated honeypot sensors, which detected repeated connection attempts consistent with unauthorized intrusion activity. The activity frequency rating of 6/10 suggests a persistent rather than sporadic threat actor, maintaining consistent scanning or exploitation efforts against target systems over the observed period.
The dominant threat category for IP 91.231.89.13 is hacking, encompassing various intrusion attempts, vulnerability exploitation and unauthorized access probes. This pattern indicates the IP is likely employed by automated attack tools or a determined actor systematically probing for weaknesses in internet-facing services. The concrete risk involves potential compromise of unpatched systems, credential exposure through brute-force attempts, or exploitation of known vulnerabilities in exposed applications, potentially leading to data breach, malware deployment or network pivoting.
Network defenders should immediately block IP 91.231.89.13 at the firewall or network edge layer. Implement aggressive rate-limiting on authentication endpoints to disrupt brute-force patterns. Enforce strong, unique credentials across all internet-facing services and enable multi-factor authentication wherever possible. Regularly audit exposed attack surfaces and ensure all systems maintain current security patches. Deploy defensive tools such as fail2ban to dynamically ban repeated offending hosts and maintain continuous monitoring for scanning activity originating from this address.