Notable Threat
IP 91.231.89.231 is a high-risk French address with a threat level of 8/10 that has generated 165 abuse reports from automated honeypot sensors over approximately seven months, indicating sustained and aggressive hacking activity against exposed network services.
The IP originates from France and operates within AS213412, which is registered to network operator ONYPHE SAS. Community and automated sensor reports began surfacing in December 2025, with continuous activity logged through June 2026, yielding an activity frequency rating of 6/10. The 165 total reports represent a substantial volume, and the 85% confidence score indicates strong evidentiary backing for the threat classification. All reported incidents fall under the hacking category, with the pattern of honeypot event detections and attack connections confirming unauthorized intrusion attempt behavior observed across multiple sensor endpoints.
The dominant threat classification for IP 91.231.89.231 centers on general hacking activity, which encompasses exploitation attempts against vulnerable services, credential-based intrusion tries, and unauthorized access probing. The sustained seven-month activity window combined with the high report count signals an automated or semi-automated campaign rather than opportunistic scanning. Exposed services such as SSH, Telnet, HTTP interfaces, or database listeners face the highest risk from this address, as general hacking toolkits often cycle through known vulnerability signatures and default credential pairs targeting these entry points.
Network operators and service administrators should immediately block or rate-limit connections from 91.231.89.231 at the firewall or network edge. Implementing fail2ban, CrowdSec, or similar dynamic blocking tools can automate this response based on honeypot and log-triggered thresholds. All exposed services should enforce strong, non-default credentials and disable unused protocols where possible. Regular patch management and intrusion detection monitoring will reduce the window of vulnerability that this address likely attempts to exploit. Continuous traffic analysis and log review for sources matching this IP's scanning signature will further harden defenses against similar threat actors.