Maximum Danger
IP 106.225.133.217 is a critical-risk address associated with 166 abuse reports and classified as an exploited host, indicating this system has been compromised and is being weaponized for malicious activity without its owner's knowledge.
According to aggregated reports from 20 automated honeypot sensors spanning August 2025 through April 2026, this Chinese IP address (AS134238, operated by CHINANET Jiangxi province IDC network) was flagged predominantly for exploited host activity and general hacking intrusion attempts. The confidence score of 64% reflects partial certainty in attribution given the volume of independent detections. Despite the extremely low activity frequency score of 0/10, the sheer number of distinct reports across multiple detection sources paints a consistent picture of ongoing compromise. The network operator's IDC infrastructure suggests this IP likely belongs to a rented cloud or data center instance, a common hosting environment for both compromised victim machines and attacker-controlled nodes.
The dominant attack vector observed against this IP involves Redis server exploitation attempts, specifically generating Suricata alerts for stream packets with invalid timestamps. This pattern indicates the compromised system is actively probing or attempting to exploit Redis instances, likely as part of a coordinated campaign to compromise additional infrastructure. As an exploited host, this machine poses a dual threat: it remains a victim requiring remediation by its owner, while simultaneously serving as an attack platform that endangers any exposed Redis services reachable from its network position.
Site operators with publicly accessible Redis deployments should immediately block this IP address at the network perimeter and implement connection authentication requirements. Deploying intrusion detection rules and employing tools such as fail2ban to dynamically block repeat offenders provides layered defense against the observed exploitation patterns. Network defenders should audit Redis access logs for similar invalid timestamp signatures and ensure instances are never exposed to untrusted networks without password protection or network-level ACLs.