High Risk
IP 91.231.89.141 is a maximum-threat address classified at a 10/10 threat level with 173 abuse reports filed across automated honeypot sensors, indicating sustained and aggressive intrusion activity originating from a French network operated by ONYPHE SAS. With a confidence score of 86% and an activity frequency rating of 8/10, this IP represents a persistent, high-risk actor whose behavior across the threat-intelligence ecosystem warrants immediate defensive action.
Analysis of the detection data reveals that automated honeypot sensors filed 173 reports concerning IP 91.231.89.141, with activity spanning September 2025 through June 2026 — a sustained campaign of approximately nine months. All 173 reported incidents map to the "Hacking" threat category, encompassing unauthorized access attempts and exploitation-oriented activity. The concentration of reports across 20 distinct honeypot sensors indicates this actor is systematically probing across multiple targets rather than conducting isolated opportunistic scans. The geographic origin in France and the AS213412 ASN operated by ONYPHE SAS place this activity within a commercial network environment, though the specific origin of the malicious traffic remains contextually unconfirmed.
The "Hacking" classification assigned to this IP encompasses general intrusion activity including vulnerability exploitation attempts, unauthorized access probing, and other mechanisms designed to compromise exposed services. For any organization with SSH, RDP, web interfaces, or similarly exposed network services, contact with an address exhibiting this behavior pattern poses a concrete risk of initial access, credential compromise, or exploitation of unpatched software. The sustained frequency of reports (8/10) confirms repeated engagement with target infrastructure rather than transient or failed scanning.
Network defenders encountering this IP should treat it as hostile and apply blocking at the perimeter firewall or web application firewall level. Implementing automated dynamic blocking via tools such as fail2ban or equivalent rate-limiting solutions can reduce the effectiveness of sustained probing. Authentication hardening — enforcing key-based authentication, strong password policies, and multi-factor authentication on exposed services — significantly reduces the impact of any successful intrusion attempt. Continuous monitoring of logs for patterns associated with this address and regular review of honeypot and community feeds will provide ongoing situational awareness regarding this and related threat actors.