Notable Threat
IP 91.230.168.67 is a critical-risk address associated with sustained hacking activity and identified as an exploited host, with 161 total reports across automated honeypot sensors spanning January to June 2026.
The IP, routed through AS213412 (ONYPHE SAS) in the United States, demonstrates an activity frequency of 8 out of 10, indicating consistent, high-volume hostile traffic. Of the 161 reports, 20 explicitly categorize the activity as general hacking attempts encompassing intrusion vectors, vulnerability exploitation, and unauthorized access probes, while one report independently flags the address as an exploited host — meaning the machine itself may be compromised and operating as an attack platform without the owner's knowledge. Detection was driven entirely by automated honeypot sensors, which logged specific attack signatures including Redis-targeted attacks and TLS protocol anomalies consistent with Suricata invalid record type alerts.
The dominant threat category is general hacking activity, which encompasses a wide spectrum of intrusion attempts targeting exposed services. The Redis-specific attack signature detected indicates the IP is actively probing for commonly misconfigured NoSQL databases, attempting to exploit weak or missing authentication and exposed network interfaces. The TLS protocol anomaly suggests the actor may be experimenting with malformed encrypted connections to evade detection or exploit vulnerable TLS implementations. The exploited host classification raises additional concern that this address may belong to a compromised machine participating in broader attack infrastructure, multiplying the potential risk to any exposed service.
Site operators should block this IP immediately at the firewall or network edge device to eliminate the threat vector. Implementing automated blocking via tools such as fail2ban can further harden authentication services against repeated login attempts. Auditing externally facing services — particularly Redis and similar NoSQL databases — to ensure strong authentication, network isolation, and up-to-date patching eliminates the specific vulnerabilities this actor targets. Organizations observing TLS anomalies in their logs should investigate for potential exploitation attempts and ensure TLS stacks are current.