Extreme Threat
IP 114.80.35.241 is a critical-risk address assessed at threat level 10/10, identified as an exploited host actively conducting Redis-based attack operations. This IP, registered to China Telecom Group under ASN AS4812 in China, has generated 359 total abuse reports across 20 independent automated honeypot sensors since August 2025. The dominant threat category — Exploited Host — indicates this system has been compromised by threat actors and is now being weaponized as an attack platform without the knowledge of its legitimate operator.
The volume and consistency of reports paint a clear picture of sustained malicious activity. With 359 total reports attributed to this single address and exploit attempts confirmed in the most recent reporting window, this IP represents an active, ongoing threat to internet-facing services. Detection occurred exclusively through automated honeypot infrastructure, with the Redis attack pattern specifically identified in the latest reports. The 71% confidence score reflects strong but not absolute attribution certainty, accounting for factors inherent in automated threat classification. Activity frequency of 3/10 suggests persistent rather than burst-style engagement, consistent with automated scanning and exploitation tooling operating continuously against target ranges.
An exploited host threat classification carries significant real-world consequences for both the target infrastructure and the broader internet ecosystem. Attackers leverage compromised systems like this one to obfuscate their true origin, distribute attack traffic, and scan for vulnerable Redis deployments. The Redis-specific attack pattern indicates the threat actors are actively probing for misconfigured or unpatched NoSQL database instances, seeking to either extract data, achieve remote code execution, or establish persistent footholds within target environments. Because the legitimate owner of IP 114.80.35.241 is unaware their system has been compromised, the malicious activity can continue uninterrupted for extended periods.
Site operators with internet-facing services should immediately block IP 114.80.35.241 at the network perimeter to prevent inbound exploitation attempts. Implementing automated defensive tools such as fail2ban can detect and respond to repeated connection patterns associated with this IP's scanning activity. Redis instances specifically should never be exposed directly to the internet without strong authentication mechanisms, and administrators should verify no unauthorized configuration changes have been introduced. Finally, consider notifying the hosting provider through standard abuse channels — reaching China Telecom Group via their published abuse handling procedures — so the compromised system owner can be alerted and remediation initiated at the source.