Severe Risk
IP 91.231.89.148 is a high-risk address associated with active hacking operations originating from French network infrastructure operated by ONYPHE SAS. With a threat level rated 10/10 and an activity frequency of 8/10, this IP has accumulated 158 abuse reports indicating persistent malicious behavior over an eleven-month observation window between August 2025 and June 2026.
Security monitoring systems detected this IP through 20 separate automated honeypot sensors, generating 158 total reports with a confidence score of 89 percent. The dominant threat classification is Hacking, accounting for 19 recent reports, while 1 report categorizes the address as an Exploited Host, suggesting the infrastructure may itself be compromised and weaponized. The network is registered to AS213412 under ONYPHE SAS, a French autonomous system operator, and the IP has demonstrated both connection-based attack patterns and malware or exploit activity consistent with intrusion attempts against exposed services.
The classification of Hacking encompasses unauthorized access attempts, vulnerability exploitation, and intrusion activities that target live systems on the internet. When an IP demonstrates this behavior with such frequency and report volume, it poses a direct threat to any publicly accessible service, particularly those with exposed authentication interfaces, unpatched software, or configuration weaknesses. The presence of malware or exploit activity in the detection data reinforces that this address is actively scanning and attacking infrastructure rather than passively probing. An 89 percent confidence score based on cross-sensor validation makes it highly probable that traffic from this IP represents genuine malicious intent rather than misclassification or benign scanning.
Network defenders should immediately block IP 91.231.89.148 at the firewall or network edge to eliminate this threat vector. Implementing strict rate-limiting on authentication endpoints, enforcing strong credential policies, and deploying automated abuse-detection tools such as fail2ban or equivalent solutions will reduce exposure to brute-force and exploitation attempts. Regular patching of internet-facing software and continuous monitoring of authentication logs for source IPs matching this address will further harden defenses against the specific attack patterns observed.