Critical Threat
IP 91.231.89.147 is a maximum-threat address operating from French infrastructure that has been linked to 164 separate incident reports over approximately seven months, with automated honeypot sensors recording persistent unauthorized access attempts against exposed services. With a threat level rated 10 out of 10 and an activity frequency score of 8 out of 10, this IP represents a clear, ongoing danger to any publicly accessible system it targets.
Threat intelligence data confirms 20 confirmed hacking incidents attributed to 91.231.89.147, detected exclusively through automated honeypot sensors between November 2025 and June 2026. The address resides within AS213412, operated by ONYPHE SAS, a French network entity. Analysis of reported attack patterns detected SSH session establishment attempts on expected service ports, indicating systematic probing for vulnerable authentication endpoints. The 88 percent confidence score reflects strong corroboration across multiple detection points, though the complete absence of community-based abuse reports alongside honeypot-only detection suggests this actor may be selectively targeting honeypot infrastructure rather than operating indiscriminately across the broader internet.
The dominant threat category for 91.231.89.147 centres on automated intrusion activity, specifically the establishment of SSH sessions against internet-facing servers. Such reconnaissance and session-initialization behaviour frequently precedes credential-based attacks or lateral movement attempts. Exposed SSH services running on standard ports are particularly vulnerable to automated tooling that systematically attempts authentication combinations or exploits known vulnerabilities in outdated server software.
Organizations with SSH services accessible from the internet should treat connections originating from 91.231.89.147 as hostile and immediately block the address at the network perimeter. Deploying certificate-based authentication alongside strong password policies significantly reduces the effectiveness of automated intrusion attempts. Implementing fail2ban or equivalent dynamic blocking tools provides adaptive protection against repeated connection attempts. Additionally, restricting SSH access to known IP ranges through firewall rules or VPN gateways eliminates exposure to untrusted sources entirely.