Elevated Risk
IP 91.231.89.214 is a high-risk address operating from French network infrastructure (ASN AS213412, ONYPHE SAS) with a threat level of 8/10 and an 86% confidence score based on 165 total abuse reports. The dominant activity detected is general hacking intrusion attempts, making this IP a significant concern for any exposed services.
Analysis of available telemetry indicates persistent activity spanning from August 2025 through June 2026, representing approximately eleven months of documented malicious behavior. All twenty recent reports specifically categorize the activity as hacking-related intrusion attempts, detected entirely through automated honeypot sensors. With an activity frequency rated 5/10, this represents consistent rather than sporadic scanning behavior. The network traffic signatures include TCP stream anomalies where spurious retransmissions suggest active reconnaissance or connection manipulation techniques targeting exposed endpoints.
Hacking activity encompasses a broad range of intrusion methodologies including vulnerability exploitation, unauthorized access attempts, and reconnaissance probes. The detected TCP stream irregularities indicate active probing of network services, potentially as a precursor to more targeted exploitation. This pattern poses concrete risk to exposed services lacking proper hardening or current security patches. The sustained report volume and extended activity window suggest this is not opportunistic scanning but persistent threat activity against reachable network resources.
Site operators should implement immediate blocking of this IP address at the firewall or network perimeter level. Deploying automated abuse-detection tools such as fail2ban can dynamically ban IPs exhibiting suspicious connection patterns. Enforcing strong authentication on all accessible services, particularly SSH and web interfaces, significantly reduces successful intrusion risk. Regular security patching and configuration auditing of exposed systems eliminates known vulnerabilities that this category of threat actor typically attempts to exploit.