Critical Threat
IP address 91.231.89.205 is a high-risk address originating from France that presents a critical threat to exposed network services, with a threat level of 10/10 and a confidence score of 89 percent based on 179 total abuse reports from automated honeypot sensors. The IP demonstrates sustained offensive activity with an activity frequency rating of 8/10, with reported connections spanning from August 2025 through June 2026, indicating persistent rather than opportunistic scanning behavior. The associated Autonomous System Number AS213412 is operated by ONYPHE SAS, a cyberthreat intelligence firm, which makes the confirmed malicious activity from this address particularly noteworthy as it originates from within the security community itself.
Detection data collected from 20 independent automated honeypot sensors confirms that this IP has been systematically probing web application infrastructure and attempting unauthorized access connections. Of the categorized reports, hacking activity accounts for 19 confirmed threat events while web application attacks represent a single additional category, with attack pattern analysis identifying both general intrusion attempts and specifically targeted ElasticPot web application honeypot probes. The concentration of reports across multiple geographically distributed honeypot sensors indicates this is not isolated probe traffic but coordinated reconnaissance or exploitation activity traversing multiple network paths.
The dominance of hacking activity in the reported threat profile suggests this IP is engaged in vulnerability scanning, credential-based attack campaigns, or exploitation of known security weaknesses in exposed services. Web application attack techniques aligned with OWASP Top 10 categories pose concrete risks including data exfiltration, service disruption, or establishing persistent access to compromised systems. The sustained 10-month reporting window with consistent high-frequency activity demonstrates a determined adversary rather than a misconfigured system or transient scanner.
Network defenders should immediately block IP 91.231.89.205 at the firewall or network edge layer given its critical threat classification and confirmed malicious intent. Implementing fail2ban or similar dynamic blocking tools that automatically respond to honeypot and intrusion detection alerts provides automated defense against repeated attack patterns. Organizations running exposed services should enforce strong authentication mechanisms, apply security patches promptly, and deploy web application firewalls to mitigate exploitation attempts. Continuous monitoring of abuse report feeds and threat intelligence platforms helps maintain updated blocklists and situational awareness regarding this and similar hostile addresses.