Critical Alert
IP 185.107.80.93 is a critical-risk address originating from France under autonomous system AS43350 (NForce Entertainment B.V.) that has accumulated 263 total abuse reports with a 94% confidence score, making it one of the most actively hostile IPs documented in recent months. The dominant threat activity combines general hacking intrusion attempts with evidence that the host itself may be compromised and weaponized, with 20 independent automated honeypot sensors across various networks confirming malicious connection attempts. The IP's activity frequency of 8/10 indicates sustained, persistent offensive operations rather than opportunistic or short-lived scanning.
The reporting window spans February 2026 through June 2026, representing approximately five months of continuous hostile engagement detected across the community sensor network. Analysis of the attack patterns reveals multiple concurrent threat vectors: the system is conducting Redis database attacks, generating Suricata intrusion-detection alerts related to malformed TLS records, and actively distributing malware or exploit payloads. The presence of "Exploited Host" classification alongside primary hacking activity strongly suggests this address belongs to a compromised server or VPS instance that threat actors have co-opted as an automated attack platform, likely without the legitimate operator's knowledge. NForce Entertainment B.V. operates the associated network infrastructure, and the Dutch-registered hosting provider may not yet be aware their resources are being weaponized.
The implications for exposed services are serious: Redis attacks target a widely-used in-memory database that, when misconfigured or exposed to the internet, can allow unauthenticated command execution, data exfiltration, or server takeover. TLS protocol anomalies detected by Suricata sensors indicate the IP may be attempting to exploit implementation flaws or conduct man-in-the-middle trafficking. The combination of malware distribution capability and persistent automated scanning makes any service accessible to this IP a potential entry point for ransomware, cryptomining malware, or further network penetration.
Site operators should immediately block IP 185.107.80.93 at the firewall or network perimeter and implement fail2ban or equivalent dynamic blocking mechanisms to auto-respond to repeated connection attempts. Redis instances should never be exposed to untrusted networks without authentication, TLS hardening, and proper network segmentation. Continuous monitoring of authentication logs for brute-force patterns originating from this address range is strongly advised, and organizations discovering sustained contact with this IP should consider notifying NForce Entertainment B.V. so the hosting provider can investigate potential compromise of their infrastructure.