Maximum Danger
IP 91.191.209.46 is a high-risk address operated by L&L Investment Ltd. in Bulgaria that has generated over 1000 abuse reports since May 2026, making it one of the most actively threatening IPs observed in recent months. This IP has been linked almost exclusively to hacking activity, specifically intrusion attempts and exploitation probes targeting exposed services. With a threat level of 10 out of 10 and an activity frequency rating of 8 out of 10, the IP reputation data indicates sustained, deliberate hostile engagement rather than opportunistic scanning. The exceptionally high confidence score of 94% across 20 independent automated honeypot sensors confirms that the malicious activity is deliberate and repeatable.
The evidence base for this assessment is robust, drawing from 1000 reports filed over approximately three months between May and July 2026. Detection came exclusively from automated honeypot sensors, which are designed to mimic vulnerable services and capture intrusion techniques without exposing real infrastructure. The consistent volume of reports over this timeframe suggests a persistent campaign rather than a one-time burst of activity. The network is registered to L&L Investment Ltd. under ASN AS57509 in Bulgaria, a routing path that places the origin within a specific commercial network environment known to security monitoring systems. The sustained reporting rate indicates that the actor behind this IP has not altered tactics despite widespread detection.
The dominant threat category, hacking, encompasses a broad spectrum of unauthorized access attempts, vulnerability exploitation and intrusion activity against exposed services. Detected patterns include network probes that generate ICMP destination unreachable responses, specifically communications where the target host administratively prohibits contact. This type of probe is a classic reconnaissance technique used to map firewall rules, identify live hosts behind filtering devices and determine network boundary configurations before launching more targeted attacks. The real-world risk is that successful reconnaissance enables subsequent exploitation of unpatched vulnerabilities or credential-based intrusion against services that accept external connections. Any service exposed to this IP faces a non-trivial probability of receiving structured probing or automated exploitation attempts.