Notable Threat
IP 91.231.89.197 is a high-risk address originating from France, operated by ONYPHE SAS under ASN AS213412, with a threat level of 8/10 and a confidence score of 91% based on 156 total reports from 20 automated honeypot sensors over a six-month period from January to June 2026. The dominant activity involves hacking-related intrusion attempts and exploited-host behavior, with the IP flagged 19 times for hacking activity and once as an exploited host. The 8/10 activity frequency indicates persistent and aggressive scanning behavior, making this address a significant threat to any exposed services.
Detection sources have recorded attack patterns consistent with connection attempts, malware and exploit activity, and Suricata alerts noting protocol mismatches in both directions. The high report volume across 20 independent honeypot sensors demonstrates broad, coordinated scanning activity rather than isolated probes. The timeframe spanning six months indicates sustained malicious intent, and the network operator ONYPHE SAS, while a legitimate entity, may be hosting a compromised system or an attack platform being leveraged without the owner's knowledge. France-based infrastructure frequently appears in European threat feeds due to the region's extensive internet exchange points and cloud hosting availability.
The Hacking category encompasses unauthorized access attempts, vulnerability exploitation, and intrusion activity that could target exposed services including SSH, RDP, web interfaces, or custom applications. The Exploited Host classification suggests this IP may itself be a compromised asset weaponized by threat actors, amplifying its danger since traffic may appear legitimate until an attack is launched. The Suricata protocol mismatch alerts indicate the IP is probing services with unusual or malformed protocol requests, a common precursor to exploitation. Real-world risk includes credential stuffing against authentication portals, reconnaissance for unpatched vulnerabilities, and potential deployment as part of a larger botnet or attack chain.
Site operators should immediately block IP 91.231.89.197 at the firewall or edge device level and implement geolocation-based blocking for non-essential French source traffic. Enforce strong authentication with multi-factor authentication on all exposed services and apply rate-limiting to prevent brute-force attempts. Keep all systems patched and update intrusion detection signatures regularly to catch the exploit activity this IP has demonstrated. Deploy defensive tools such as fail2ban to automatically identify and block repeated connection attempts from this address and similar patterns.