Critical Threat
IP 91.231.89.213 is a high-risk address originating from France that has generated 169 abuse reports with a maximum threat score, indicating sustained malicious activity detected across 20 automated honeypot sensors over approximately eleven months of active observation.
The IP operates within network AS213412 under the operator ONYPHE SAS, a French cybersecurity company, and has been flagged with a confidence score of 86 percent and an activity frequency rating of 8 out of 10. The first report surfaced in August 2025, with activity continuing through June 2026, demonstrating persistent rather than opportunistic behaviour. The overwhelming majority of reports—19 out of 20 categorised incidents—relate to general hacking activity including intrusion attempts and exploitation probes, while a single report documents web application attack activity. The detection data indicates this address was observed making direct attack connections and probing honeypot systems configured to emulate web applications, suggesting systematic reconnaissance and exploitation attempts against internet-facing services.
The dominant hacking classification encompasses a broad spectrum of intrusion activities, from credential brute-forcing to vulnerability scanning and exploitation attempts against unpatched services. This IP's sustained, high-frequency engagement with honeypot infrastructure implies automated tooling rather than manual probing, increasing the likelihood that any exposed service in the target organization's environment would be systematically scanned and attacked. Web application attacks add another dimension, potentially targeting OWASP Top 10 vulnerabilities such as injection flaws, broken authentication, or sensitive data exposure if web-facing applications are reachable.
Operators should immediately block this IP at the network perimeter firewall and implement fail2ban or similar dynamic blocking tools to automatically mitigate repeated attack patterns. All internet-facing services should be audited for unnecessary exposure, with strong authentication, rate limiting, and web application firewall rules applied where appropriate. Continuous monitoring for scanning activity from this address and routine security patching of systems will reduce the attack surface available to this and similar threats.