Severe Risk
IP 91.231.89.144 is a high-risk address operating from French network infrastructure that has generated 175 abuse reports between August 2025 and June 2026, with an activity intensity rated 8 out of 10 and a threat confidence score of 88 percent. All confirmed reports classify this IP's activity under the hacking threat category, with automated honeypot sensors across multiple installations consistently flagging connection attempts and suspicious secure shell session behaviour originating from this address.
The detection data reveals a sustained, high-frequency campaign lasting approximately ten months, with 20 distinct automated honeypot sensors documenting the activity. Network telemetry from the associated autonomous system AS213412, operated by ONYPHE SAS, indicates the source is routed through French infrastructure. The honeypot alerts specifically reference Suricata signatures flagging active SSH sessions on expected ports and application-layer protocol mismatches, patterns consistent with credential-guessing or session-hijacking reconnaissance activity against exposed secure shell services.
The dominant threat vector involves unauthorized access attempts against exposed SSH daemons, a common attack surface on internet-connected Linux systems and network equipment. Attackers leverage these services as initial entry points into enterprise environments, often deploying the compromised host as a pivot point for lateral movement or deploying persistent backdoors. The volume and persistence of reports against IP 91.231.89.144 suggest an automated scanning or brute-force operation rather than isolated probing, increasing the risk that any vulnerable or misconfigured SSH service encountering this traffic could be compromised.
Network administrators should implement fail2ban or equivalent dynamic firewall rules to automatically block repeated authentication failures from this source, enforce key-based authentication and disable password authentication entirely on SSH services, apply strict connection rate-limiting at the network edge, and monitor authentication logs for any emerging patterns matching this source address.