Critical Alert
IP 36.99.41.23 is a critical-risk address originating from Luoyang, Henan Province, China, definitively identified as an exploited host conducting unauthorized Redis interactions against honeypot sensors, with 160 abuse reports filed through automated detection systems between September and November 2025.
The IP operates within AS137687 and has accumulated these reports with a 69% confidence score, indicating strong but not absolute certainty in attribution. The high volume of reports despite the zero activity frequency metric suggests this address was highly active during the September-November 2025 window but has since become dormant, possibly due to takedown efforts, rotation to alternative infrastructure, or successful remediation by the original network operator. Twenty of those reports specifically categorize the activity as an exploited host, meaning the source system was almost certainly compromised and being remotely controlled without the owner's knowledge or consent. The Redis attack pattern detected indicates attempts to exploit insecure Redis deployments, typically targeting exposed instances to achieve code execution through malicious Lua scripts, SSH key injection, or cron job manipulation.
Exploited hosts pose distinct risks compared to directly operated attack infrastructure because they represent systems belonging to unsuspecting victims that have been weaponized, meaning the real owner may be unaware their resources are being used maliciously. Redis exploitation specifically can lead to complete system compromise, data exfiltration, or use of the compromised host as a pivot point for further network intrusion. Organizations with internet-facing Redis instances should verify that authentication is enabled, binding is restricted to localhost only, and that network exposure is minimized to prevent unauthorized command execution.
Site operators should block IP 36.99.41.23 at the network perimeter and implement fail2ban or similar dynamic blocking tools to automatically mitigate continued probing. Patching Redis to the latest stable version, disabling dangerous commands, and using firewall rules to restrict access to Redis ports are critical defensive measures. Organizations receiving abuse reports for this address should consider notifying the hosting provider in AS137687 so the compromised system owner can be alerted and remediation initiated. Continuous monitoring of Redis access logs for suspicious commands from this IP range and implementation of network segmentation to limit lateral movement potential are also advisable.