Maximum Danger
IP 91.191.209.118 is a high-risk address originating from Bulgaria that has accumulated 1,163 abuse reports in a concentrated three-month window between April and July 2026, with a threat level rated 10/10 and an activity frequency of 8/10 indicating sustained, aggressive malicious behavior against exposed services.
The detection data shows this address was flagged 20 times specifically for hacking activity by automated honeypot sensors, with the earliest reports dating to April 2026 and the most recent in July 2026. The volume of total reports combined with the elevated confidence score of 94 percent suggests this is not isolated or opportunistic scanning but rather a persistent actor conducting sustained intrusion attempts. Geographically mapped to Bulgaria and routed through ASN AS57509, this address operates within a commercial network allocation, and the pattern of activity points to automated tooling rather than manual probing. The detection sources span multiple honeypot sensors, indicating the address has been observed across varied network environments.
The dominant threat category of hacking encompasses intrusion attempts, vulnerability exploitation and unauthorized access attempts, which together represent the most concrete real-world risk to exposed services. The observed ICMP-based communication patterns suggest reconnaissance activity designed to map network defenses and identify filtering gaps before launching further exploitation. A threat level this severe indicates successful compromise attempts or high-confidence exploit delivery, meaning any service exposed to this address without hardened controls faces immediate risk of unauthorized access, data exfiltration or deployment of secondary payloads.
Site operators should immediately block this address at the network perimeter and consider blocking the broader allocation range from AS57509 until activity subsides. Deploying automated blocking tools such as fail2ban alongside strict rate-limiting on authentication endpoints significantly raises the cost of successful intrusion. Enforcing key-based authentication, strong password policies and account lockout thresholds on any exposed services eliminates low-hanging fruit for credential-based attacks. Regular review of intrusion detection signatures and traffic logs will determine whether any probes have already reached internal infrastructure, enabling containment before lateral movement occurs.