High Risk
IP address 91.231.89.51 is a high-risk address assessed at 8/10 threat level with 91% confidence, linked primarily to hacking activity including intrusion attempts and unauthorized access scanning. This IP has generated 169 total abuse reports from 20 automated honeypot sensors over a five-month window between January and May 2026, indicating persistent and aggressive malicious behavior originating from French network infrastructure operated by ONYPHE SAS under autonomous system AS213412.
The data reveals sustained hostile activity with an 8/10 frequency rating across the reported period. Of the categorized threats, hacking-related activity dominates with 19 distinct reports, supplemented by a single VoIP fraud report. The honeypot detections specifically captured an SSH session in progress on a commonly targeted port, alongside patterns consistent with VoIP exploitation attempts. The volume of reports and consistency of activity over four months demonstrates an organized, deliberate campaign rather than opportunistic scanning, with this address maintaining poor IP reputation across security monitoring systems.
Hacking activity at this scale typically involves automated scanning for vulnerable services, credential stuffing against exposed authentication interfaces, and exploitation attempts against unpatched systems. The detected SSH session indicates the operator is actively attempting to establish persistent access to target systems, potentially deploying payloads or harvesting credentials for further exploitation. VoIP fraud activity suggests the infrastructure may additionally be leveraged to make unauthorized calls to premium-rate numbers for direct financial gain, exploiting phone systems that lack proper call authentication controls. Together, these attack patterns represent both direct system compromise risks and financial fraud vectors.
Network defenders should block this address at the firewall level and implement strict inbound traffic policies for all exposed services. Authentication hardening is critical, particularly for SSH access; deploy key-based authentication, disable root login, and consider implementing fail2ban or similar tools to automatically block repeat offenders after failed login thresholds. Monitor call records and telephony billing for unauthorized premium-rate or international dial patterns to detect potential VoIP fraud. Ensure all exposed services remain patched and current, employ network segmentation to limit lateral movement, and maintain intrusion detection monitoring to identify and respond to similar scanning activity from adjacent address ranges.