Maximum Danger
IP address 91.231.89.135 is a high-risk threat actor operating from French network infrastructure with a threat level of 10 out of 10 and 157 reported abuse incidents. The address has demonstrated sustained malicious activity from October 2025 through May 2026, with an activity frequency rated 8 out of 10, indicating persistent and repeated engagement with target systems. The dominant threat categories include general hacking activity encompassing intrusion attempts and exploitation of vulnerabilities, alongside specific targeting of Internet of Things devices.
Security monitoring systems recorded 157 abuse reports originating from 20 distinct automated honeypot sensors, yielding a 91 percent confidence score in the assessment of malicious intent. The reports span approximately seven months, confirming this is not isolated or opportunistic scanning but sustained hostile operation. The IP is routed through AS213412 operated by ONYPHE SAS, a French network operator. Observed attack patterns include generic connection attempts and activity consistent with IoT device reconnaissance and exploitation, suggesting the operator employs automated tooling to identify and compromise poorly secured connected devices and vulnerable services exposed to the internet.
Hacking activity of this severity involves systematic attempts to gain unauthorized access through exploitation of known vulnerabilities, brute-force authentication attacks, and probing for misconfigured services. When combined with IoT targeting, the risk extends to compromise of smart devices, cameras, routers, and other connected equipment that frequently ship with weak default security configurations. The sustained activity frequency confirms an active automated campaign rather than transient scanning, meaning exposed services face repeated and persistent threat exposure over extended periods.
Site operators should immediately block this IP address at the network perimeter firewall or through intrusion prevention systems to terminate ongoing and future hostile connections. All internet-facing services should enforce strong authentication mechanisms, with SSH access restricted to key-based login where applicable, and tools such as fail2ban deployed to automatically detect and block brute-force patterns. Systems must be kept current with security patches, and IoT devices should be isolated on dedicated network segments away from critical infrastructure. Continuous monitoring for connection attempts matching this threat profile will support early detection of related activity from adjacent addresses.