Extreme Threat
IP 106.13.124.241, registered to Beijing Baidu Netcom Science and Technology Co., Ltd. in China under ASN AS38365, presents a critical threat level of 10/10 based on 255 total abuse reports submitted over an eleven-month observation window from August 2025 through June 2026. Automated honeypot sensors documented sustained malicious activity originating from this address, with the dominant threat classification identifying it as an exploited host being weaponised for external attacks without the knowledge of its rightful operator. The IP reputation for this address is severely compromised, and network defenders should treat all incoming connections from this source as hostile until evidence suggests otherwise.
The dataset reveals consistent malicious behaviour at moderate activity frequency (3/10) across the reporting period, with all 20 most recent reports categorising this address specifically as an exploited host. The 72% confidence score indicates a strong analytical basis for the threat assessment, though some uncertainty remains regarding the full scope of compromise or potential attribution nuances. The Redis attack pattern detected from this host suggests exploitation of a specific database service vulnerability or misconfiguration, a technique frequently employed by threat actors to gain initial access or establish persistence within target environments. Community reports and honeypot telemetry together paint a coherent picture of a compromised system now operating as an attack platform.
An exploited host designation indicates that IP 106.13.124.241 belongs to a machine that has been compromised, likely through vulnerability exploitation or credential-based attack, and is now being remotely controlled to conduct offensive operations against third-party targets. In the context of Redis attacks, this typically means the compromised system is scanning for exposed Redis instances or attempting known command-injection techniques to achieve unauthorised code execution on vulnerable database servers. The real-world risk is that organisations with internet-facing Redis deployments without proper authentication or network restrictions become targets for automated exploitation tools operated from this compromised infrastructure.