Extreme Threat
IP 80.66.83.80 is a critical-risk address operating from Russia within AS216473 that has generated 1,929 abuse reports across automated honeypot sensors since March 2026, with hacking activity representing its dominant threat profile at a threat level of 10/10 and an activity frequency rating of 8/10. The volume and consistency of malicious connection attempts from this IP make it one of the most actively hostile addresses observed within the reporting window, warranting immediate defensive action from any exposed service.
The 1,929 total reports were compiled over approximately six months, from first sightings in March 2026 through August 2026, with 20 distinct automated honeypot sensors contributing data. Of the categorized reports, hacking-related activity accounts for the overwhelming majority, with 20 distinct incidents classified under that category alongside 2 classified as exploited-host behaviour. Attack-pattern metadata associated with this IP references general attack connections, malware or exploit activity, and specifically Redis-targeting attack connections, indicating a deliberate focus on exploiting improperly secured Redis deployments that are commonly left exposed to the internet without authentication mechanisms in place.
The dominant hacking activity pattern suggests automated scanning and exploitation attempts against internet-facing services, with a documented emphasis on Redis servers, which frequently run with default configurations that permit unauthenticated access. An IP maintaining this level of sustained, high-frequency hostile connectivity over six months poses a concrete risk to any publicly accessible service, particularly unpatched or misconfigured database and application-layer targets. The 10/10 threat score and 8/10 activity frequency confirm that this address is not a transient or low-volume source but an persistent attack platform actively probing for exploitable entry points across the internet.
Operators should block 80.66.83.80 at the network perimeter or firewall level immediately, and consider implementing automated dynamic blocking solutions such as fail2ban to respond to repeated connection attempts in real time. Redis instances and other database services should never be exposed to untrusted networks without strong authentication, ACL controls, and network-layer restrictions in place. Maintaining comprehensive logging of inbound connection attempts from this address will support incident investigation if any attempted compromise occurs. Regular review of internet-facing service configurations and prompt patching cycles will reduce the window of opportunity for any exploitation attempt originating from addresses of this threat profile.