Critical Alert
IP 182.92.181.218 is a critical-risk address that has been flagged 224 times by automated honeypot sensors since October 2025, with the most recent confirmed activity in May 2026, indicating an active exploited-host threat originating from Alibaba cloud infrastructure in China.
The address, registered to Hangzhou Alibaba Advertising Co.,Ltd. under autonomous system AS37963, has generated reports across 20 distinct automated honeypot sensors, with exploitation attempts matching patterns associated with Redis server attacks. Despite a relatively low activity frequency score of 2 out of 10, the consistent volume of abuse reports over approximately seven months demonstrates persistent scanning and exploitation behaviour. The 65% confidence score reflects that while the threat is clearly documented, attribution of the ultimate source remains partially uncertain due to the nature of compromised infrastructure. This IP has been continuously operating as an attack platform without apparent intervention from its legitimate operator.
An exploited host represents one of the most dangerous categories in network threat intelligence because the attacking infrastructure is itself a victim, often running attack tooling installed by threat actors without the knowledge of the system owner. In this case, the Redis exploitation pattern suggests the compromised server may have been leveraged to scan the internet for vulnerable Redis instances or to launch further attacks against other targets in a distributed fashion. The compromised nature of the host means blocking this IP protects against a genuine, ongoing threat while the legitimate operator remains unaware of the compromise.
Site operators should immediately block IP 182.92.181.218 at the network perimeter and implement fail2ban or similar dynamic firewall rules to automatically reject repeated connections from this source. Ensuring Redis instances are bound to localhost only, protected by strong authentication and TLS encryption, significantly reduces the attack surface for this exploitation vector. Monitoring inbound connection logs for scanning behaviour matching this address's patterns will help identify additional compromised infrastructure in the same network block.