High Risk
IP 117.80.234.157 is a high-risk address originating from Chinanet's network in China that poses a significant threat to internet-facing systems, exhibiting port-scanning behavior and unauthorized access attempts with a threat level of 8 out of 10 based on 176 abuse reports from 20 automated honeypot sensors. The address, registered to AS4134, was first flagged in September 2025 and remained active through May 2026, demonstrating persistent scanning activity over an eight-month period with moderate frequency scoring 5 out of 10 for ongoing activity.
The detection data reveals a clear reconnaissance and exploitation pattern: the dominant activity involves Zmap user-agent port scans detected by network intrusion sensors, indicating systematic probing of exposed services across targeted networks. Additionally, automated honeypots logged Redis attack attempts and stream-level anomalies consistent with TCP manipulation techniques, suggesting this address is actively attempting to compromise specific service implementations. The 176 total reports across 20 independent sensor sources substantiate a confidence rating of 69 percent, with 17 hacking-category reports and 14 port-scan reports dominating the recent telemetry alongside 2 confirmed exploited-host classifications.
Port scanning conducted with Zmap represents a serious initial attack vector because it rapidly enumerates open services and vulnerabilities across target infrastructure, enabling attackers to prioritize exploitation of misconfigured or outdated systems. The presence of Redis-specific attack patterns indicates deliberate targeting of NoSQL database instances, while spurious TCP retransmission alerts suggest potential man-in-the-middle or session-hijacking reconnaissance. An exploited-host classification implies this address may originate from a compromised system being weaponized without its owner's knowledge, which is common in botnet recruitment or residential proxy abuse. The combination of reconnaissance scanning and targeted application-layer attacks creates a compound risk for any exposed services.
Site operators should immediately block IP 117.80.234.157 at the firewall or load-balancer level and implement geo-based access restrictions if China-based connections are not expected. Configuring fail2ban or equivalent dynamic blocking tools to parse honeypot logs will automate temporary bans upon detecting similar scan patterns. Exposed services should be minimized to essential ports only, and Redis instances specifically should be bound to localhost with strong authentication and network-level access controls. Continuous monitoring of authentication logs for brute-force patterns originating from this address range is strongly recommended, along with ensuring all internet-facing software receives timely security patches.