Notable Threat
IP 220.181.1.163 is a high-risk address originating from China that has been linked to sustained reconnaissance and exploitation activity, including coordinated port-scanning campaigns and targeted database attacks. With a threat level of 8 out of 10 and 159 abuse reports logged across automated honeypot sensors over approximately eleven months, this IP demonstrates a persistent pattern of malicious behavior that poses a concrete risk to exposed services worldwide.
The activity against this address was first documented in August 2025 and continued through June 2026, with an activity frequency rated at 6 out of 10. The dominant threat categories detected are Hacking (15 reports), Port Scanning (14 reports), and Exploited Host activity (6 reports). Network reconnaissance was conducted using Zmap, a high-speed port scanner that generates distinctive User-Agent signatures detected by Suricata intrusion-prevention systems. Additionally, multiple automated sensors logged attempts to compromise Redis database services, with some connections triggering Suricata alerts for stream anomalies and invalid packet timestamps, suggesting either aggressive scanning or attempted exploitation of vulnerable instances. The IP resides in AS23724, operated by IDC, China Telecommunications Corporation, a major Chinese state-owned telecommunications provider.
Port-scanning activity of this nature serves as reconnaissance, mapping open services and potential entry points before launching targeted attacks. When combined with Redis exploitation attempts, the threat profile indicates an actor systematically probing for misconfigured or unpatched database instances to harvest data or establish persistent access. The presence of "Exploited Host" classifications in the reporting data raises the possibility that this IP address may itself be running on a compromised system, weaponized by a third party without the owner's knowledge to conduct attacks against other targets.
Defensive measures should include immediate blocking of this IP at the network perimeter firewall, implementation of fail2ban or similar dynamic blocking tools to auto-respond to scanning patterns, and strict firewall rules limiting inbound access to Redis and other database services to authorized hosts only. All exposed services should be audited for proper authentication, encryption, and patching status. Organizations observing similar scanning activity should consider notifying the upstream provider regarding the potential compromised host.