Severe Risk
IP 91.167.45.239 is a high-risk address assessed at a threat level of 10/10 that has been classified as an exploited host, indicating this French server has been compromised and is actively being weaponised by threat actors without its owner's knowledge. With 331 total abuse reports filed through automated honeypot sensors and consistent re-detection throughout September 2025, this IP represents a genuine danger to any internet-facing service it targets.
Analysis of the detection data reveals all 20 recent reports categorise this address under the exploited host classification, with the activity linked to malware and exploit-related behaviour. The IP traces to a French network operated by Free SAS under ASN AS12322. The moderate confidence score of 63% reflects typical uncertainty in attributing malicious activity to specific threat actors, yet the sheer volume and consistent pattern of reports across automated honeypot sensors provides sufficient grounds for treating this address as hostile. The low activity frequency score of 0/10 may indicate that the compromised host operates intermittently or conservatively to avoid detection, which is a common tactic for established backdoors and botnet nodes.
An exploited host differs from a directly attacking infrastructure IP because the system itself is a victim whose resources are being co-opted for malicious purposes. In this case, the host has been observed engaging in malware distribution and exploit delivery, meaning it likely participates in scanning for vulnerable services, spreading malicious payloads to other systems, or serving as a relay for command-and-control communications. The real-world risk extends beyond the immediate target—if your systems receive connections or payloads from this IP, you may be the next victim whose machine joins this threat ecosystem. The dual exposure created by exploited hosts means both the compromised owner and targeted organisations face tangible harm.
Site operators should immediately block this IP at network borders and implement automated blocking via tools such as fail2ban to respond to repeated hostile connection attempts originating from this address. Enhanced monitoring should be deployed for inbound connections from similar French IP ranges on ports commonly associated with exploit kits and malware delivery. Organisations should audit their exposed services for vulnerable configurations that could facilitate compromise, enforce multi-factor authentication on all remote access channels, and ensure logging captures sufficient detail to identify any successful connection attempts from this or related sources. Proactive notification to Free SAS regarding this compromised subscriber account would support broader community defence efforts.