Severe Risk
IP address 91.231.89.235 is a critical-risk address linked to sustained hacking activity originating from French network infrastructure. With a threat score of 10 out of 10 and 157 abuse reports logged between January and June 2026, this IP exhibits an activity frequency rating of 8 out of 10, indicating aggressive and continuous hostile probing detected by automated honeypot sensors. The IP reputation for this address is severely negative, and the volume of reports within a compressed timeframe signals a persistent threat actor rather than opportunistic scanning.
Community reports and automated honeypot detections confirm 20 distinct hacking-category incidents attributed to 91.231.89.235, with the last confirmed report filed in June 2026. The address routes through AS213412, operated by ONYPHE SAS, a French entity. Detection telemetry captured attack connection attempts accompanied by Suricata alerts indicating protocol mismatch anomalies in both communication directions, consistent with reconnaissance and exploitation techniques designed to probe service vulnerabilities and evade detection mechanisms.
The dominant threat category for this address is general hacking activity, which encompasses intrusion attempts, unauthorized access probes, and exploitation of vulnerable services. The protocol anomaly alerts suggest the attacker is actively testing how target systems negotiate network communication protocols, a common precursor to exploitation or credential-based attacks. Real-world risk includes compromised services, data exposure, or pivoting from this reconnaissance into deeper network penetration if exposed services remain unhardened.
Site operators should block 91.231.89.235 at the firewall level and monitor for any subnet overlap or related activity patterns. Implementing automated blocking tools such as fail2ban, enforcing strong authentication on exposed services, and maintaining regular patch cycles for internet-facing applications significantly reduces vulnerability to this class of threat. Continuous network traffic analysis will further help identify whether the probing has successfully mapped open ports or services for future targeting.