Severe Risk
IP address 139.198.30.179, registered in China and operated by Yunify Technologies Inc. under ASN AS59078, represents a critical threat with a maximum threat level of 10 out of 10. This address has been flagged as an exploited host in 20 recent reports, indicating that it has been compromised and weaponized by threat actors to conduct automated attacks against external targets. With 206 total abuse reports and a detection rate across 20 automated honeypot sensors, this IP poses an immediate danger to any exposed service it encounters.
The activity timeline spans from October 2025 through May 2026, demonstrating persistent malicious behavior over approximately seven months. The confidence score of 71% reflects strong analytical certainty that this host is actively engaged in hostile operations. The activity frequency rating of 4 out of 10 suggests moderate but consistent attack waves rather than sporadic spikes. The detection footprint extends across multiple honeypot sensors, confirming that this compromised system is systematically probing and attacking a broad range of targets on the internet.
An exploited host classification means that IP 139.198.30.179 belongs to a machine that has been secretly compromised, often through unpatched vulnerabilities or credential compromise, and is now functioning as a remotely controlled attack platform. The specific attack pattern identified involves Redis database targeting, where this bot attempts to exploit misconfigured or exposed Redis instances. For organizations running Redis without proper network restrictions or authentication, this translates to immediate risk of unauthorized data access, data corruption or deletion, and potential server takeover used to further propagate attacks.
Network defenders should implement immediate blocking of this IP address at the firewall or intrusion prevention system level. Organizations running Redis should enforce authentication requirements, bind the service to localhost only, and avoid running Redis in publicly accessible network segments. Deploying fail2ban or similar dynamic blocking tools can automatically mitigate repeated connection attempts from known malicious sources. Additionally, consider filing an abuse report with Yunify Technologies Inc. to alert them that AS59078 infrastructure has been compromised and is being used for malicious activity.