IP Address

91.227.37.60

IPv4 Public
FR FR
AS200780
Eurofiber France SAS
200 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
8/10 Threat
100% Confidence
200 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
FR
FR Location
Eurofiber France SAS ASN 200780
200 Reports
Mixed Data Source

Significant Threat

IP address 91.227.37.60, registered to Eurofiber France SAS and geolocated in France, presents a high-risk threat profile with a calculated threat level of 8 out of 10 based on 200 total abuse reports and a confidence score of 100%. The address demonstrates persistent WordPress reconnaissance and authentication attack behavior, making it a confirmed threat vector requiring immediate defensive action from operators running web-facing content management systems.

Detection data shows 91.227.37.60 generating activity across 12 automated honeypot sensors and 8 independent community reports, with both initial and most recent observations occurring between April and May 2026. The dominant threat categories include general hacking attempts (16 reports), brute-force authentication attacks (15 reports), and WordPress-specific login brute-forcing (11 reports), supplemented by distributed denial-of-service activity, user enumeration probes, and plugin vulnerability exploitation attempts. This concentration of WordPress-targeted activity indicates systematic reconnaissance against a specific platform rather than generic port scanning.

The attack patterns observed against honeypot infrastructure reveal coordinated exploitation of WordPress REST API endpoints for user enumeration, credential stuffing against authentication portals, and brute-force attempts using common administrative credential pairs. Each technique individually poses moderate risk, but their combined deployment suggests an automated credential compromise campaign capable of silently compromising WordPress installations that lack multi-factor authentication or strong password policies. Successful exploitation could grant persistent backdoor access to compromised websites for content manipulation, malware distribution, or further lateral movement.

Site operators should immediately block or rate-limit connections from 91.227.37.60 at the network perimeter, enforce multi-factor authentication on all administrative accounts, rename default administrative paths, and implement fail2ban or equivalent intrusion prevention rules targeting repeated authentication failures and suspicious API requests. Regular security audits, prompt WordPress core and plugin updates, and web application firewall rules blocking enumeration patterns provide additional protective depth against similar reconnaissance activity.

More threatening than 82% of monitored IPs

Threat Categories

Brute-Force 23
Hacking 20
WP Login Brute Force 13
DDoS Attack 6
WP User Enumeration 2
WP Plugin Exploit 1

Technical Details

Brute-force attacks systematically attempt password combinations against authentication systems.

Recommended Mitigations

Implement rate limiting, account lockout policies, multi-factor authentication, and fail2ban.

Behavioral Analysis

Activity Pattern: Sporadic

Irregular burst activity pattern indicates intermittent use of a compromised system.

First Observed 13. May 2026
Last Activity 24. May 2026
Recent (7 days) 0 incidents

High-Risk Network Association

This IP belongs to a network (ASN 200780) with elevated threat levels. The ISP Eurofiber France SAS hosts multiple reported malicious addresses, suggesting systemic security issues or permissive policies.

Network-wide patterns may indicate this is part of a larger malicious infrastructure.

Security Recommendations

Implement adaptive blocking rules.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 8/10 High
Confidence Score 100% Verified

Confidence History

15. May 2026 - 24. May 2026
100% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Brute-Force WP Plugin Exploit +1 Honeypot 75%
Hacking DDoS Attack Community 75%
Hacking DDoS Attack Community 75%
Hacking DDoS Attack Community 75%
WP User Enumeration Community 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Hacking DDoS Attack Community 75%
Brute-Force Community 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Brute-Force Community 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Brute-Force Community 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Brute-Force Community 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Brute-Force Community 75%
Hacking Brute-Force WP Login Brute Force Honeypot 75%
Brute-Force Community 75%
Hacking DDoS Attack Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Hacking DDoS Attack Community 75%
Brute-Force Community 75%

Technical Details

Basic Information

IP Address
91.227.37.60
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
FR FR
ASN
AS200780
ISP
Eurofiber France SAS

DNS Information

Reverse DNS
reverse.as200780.net
PTR Record
Yes
Connection Type
Static

Statistics

Total Reports
200
First Reported
17 Apr 2026
Last Reported
24 May 2026, 16:19

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS200780
Eurofiber France SAS
FR FR

Network Threat Assessment

8/10
This network has a high threat level with significant malicious activity reported across multiple IPs.

Network Statistics

1
Total IPs Monitored
34
Total Reports
34
Reports per IP

Network Context

This IP address belongs to Eurofiber France SAS (AS200780), which manages 1 IP addresses in our monitoring system. Out of these, 34 have been reported for suspicious activities, resulting in a network-wide threat level of 8/10.

Network warning: This network has elevated threat levels. Exercise caution when interacting with IPs from this ASN.

Comparative Analysis

How this IP compares to others in our threat intelligence database

82 %

Global Threat Ranking

This IP is more threatening than 82% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 199,234 reported IPs worldwide

Threat Level 8/10 avg: 5.3 ++
Total Reports 200 avg: 23 ++

Geographic Comparison

Compared against 4,067 IPs in FR

Threat Level 8/10 country avg: 5.8 +
Total Reports 200 country avg: 31 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

186,914 threat incidents tracked globally • Last 24h: 18,893 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,421 20.6%
  2. 02
    IN
    India IN
    28,931 15.5%
  3. 03
    CN
    China CN
    26,004 13.9%
  4. 04
    BR
    Brazil BR
    10,236 5.5%
  5. 05
    DE
    Germany DE
    7,138 3.8%
  6. 06
    SG
    Singapore SG
    6,475 3.5%
  7. 07
    ID
    Indonesia ID
    5,522 3%
  8. 08
    RU
    Russia RU
    4,700 2.5%
  9. 09
    PK
    Pakistan PK
    4,646 2.5%
  10. 10
    NL
    Netherlands NL
    4,354 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "91.227.37.60",
    "threat_level": 8,
    "confidence_score": 100,
    "total_reports": 200,
    "country_code": "FR",
    "isp_name": "Eurofiber France SAS",
    "asn": "200780",
    "first_reported": "2026-04-17 11:50:22",
    "last_reported": "2026-05-24 16:19:21",
    "exported_at": "2026-06-09T07:07:25+02:00",
    "source": "https://reportedip.de/ip/91.227.37.60/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.