Maximum Danger
IP 91.231.89.242 is a critical-risk address that has generated 170 abuse reports from automated honeypot sensors since August 2025, with the vast majority classified as hacking activity indicating sustained intrusion attempts against exposed services.
According to data compiled through June 2026, this French IP address operating through AS213412 (ONYPHE SAS) has been reported with a threat level of 10 out of 10 and a confidence score of 89 percent, reflecting a highly reliable assessment of malicious behaviour. The 170 total reports represent significant abuse volume, while an activity frequency rating of 8 out of 10 demonstrates that this IP maintains persistent engagement with target systems across its reporting window. All 20 most recent threat reports categorise the activity as hacking, suggesting a consistent and focused intrusion methodology rather than opportunistic scanning.
The dominant threat category of hacking encompasses a broad range of intrusion activity, including exploitation attempts against vulnerable services, credential guessing, and probing for entry points into network infrastructure. For organisations running publicly accessible services such as SSH, RDP, web servers, or administrative interfaces, an IP with this threat profile represents a concrete risk of unauthorized access if proper hardening measures are absent. Attackers leveraging this address are actively attempting to identify and compromise weak or unpatched systems.
Site operators should treat connections originating from 91.231.89.242 as hostile and implement immediate blocking at the network perimeter firewall. Deploying fail2ban or equivalent dynamic blocklist tools can automate this process and provide ongoing protection against repeated intrusion attempts. All exposed services should enforce strong, unique passwords and consider key-based authentication where feasible. Regular security patching, implementation of intrusion detection monitoring, and audit logging for failed authentication attempts will further reduce the attack surface and enable rapid identification of any successful compromise.