Critical Alert
IP address 91.231.89.138, allocated to French network operator ONYPHE SAS under ASN AS213412, represents a maximum-threat-level address with 158 abuse reports filed across an active detection period spanning August 2025 through June 2026. This IP has earned a threat level rating of 10 out of 10 and demonstrates an activity frequency score of 8 out of 10, indicating persistent and aggressive malicious behaviour against exposed network infrastructure.
Security monitoring systems detected this address through 20 automated honeypot sensors and community-driven abuse reporting mechanisms. The volume of reports, combined with a 90% confidence score in threat attribution, strongly corroborates that 91.231.89.138 is actively engaged in malicious network activity rather than exhibiting incidental or benign behaviour. The geographic concentration in France and its assignment to ONYPHE SAS provides network-level context, though the IP's behaviour pattern indicates it may be part of a compromised infrastructure or a deliberately hostile endpoint operating across multiple jurisdictions.
The dominant threat category logged against this IP is general hacking activity, which encompasses intrusion attempts, exploitation of vulnerable services, and repeated unauthorized access campaigns. This pattern suggests that exposed services encountering 91.231.89.138 may be subjected to credential brute-forcing, vulnerability scanning, or exploitation of known software weaknesses. The sustained activity frequency implies this address is not a transient threat but an established actor in automated attack campaigns targeting internet-facing systems.
Network defenders should immediately block 91.231.89.138 at the firewall or network edge to eliminate contact with this source. Deploying or strengthening fail2ban or equivalent dynamic blocklist tools on exposed services such as SSH, RDP, and web interfaces provides automated response to repeated connection attempts. Ensuring all systems remain current with security patches, implementing strong multi-factor authentication, and maintaining intrusion detection monitoring will reduce susceptibility to the intrusion methodologies this address employs. Regularly reviewing authentication logs for patterns consistent with brute-force or scanning activity from this IP will support ongoing threat assessment and incident response readiness.