Critical Threat
IP 81.94.156.35 is a critical-risk address originating from Russian network infrastructure AS8595 (OOO WestCall Ltd.) that has generated 925 abuse reports from automated honeypot sensors within a concentrated January–February 2026 timeframe, with hacking activity and exploited-host indicators dominating recent telemetry.
The volume of reports is substantial at 925 total, detected across 20 distinct automated honeypot sensors, indicating persistent and distributed probing behaviour rather than isolated scanning. The reported activity categories break down primarily into Hacking (18 recent reports) and Exploited Host (2 recent reports), suggesting this address may simultaneously serve as an active intrusion platform and potentially operate as a compromised system itself. The confirmed attack patterns include general attack connections, malware and exploit activity, and notably Redis-targeted attack sequences. With a threat level of 10/10 and a 62% confidence score, analysts assign high conviction to the malicious classification despite the relatively short active window spanning approximately two months.
Hacking activity as recorded here encompasses intrusion attempts, vulnerability exploitation, and unauthorized access probing against exposed services. When combined with Redis-specific attack patterns, this strongly implies credential stuffing or unauthenticated command execution attempts against Redis installations that lack proper network exposure controls or authentication hardening. The presence of exploited-host indicators suggests the address may be allocated to an unwitting organization whose infrastructure has been commandeered, meaning WestCall Ltd. or their downstream customer could be a victim themselves. Regardless of ultimate attribution, the operational risk to any service exposed to this IP is significant.
Defensive measures should include immediate blocking or rate-limiting of traffic originating from 81.94.156.35 at the network perimeter, particularly for Redis service ports and SSH endpoints. Organizations running Redis should verify that authentication is enforced with strong passwords and that instances are not exposed to untrusted networks. Deploying fail2ban or equivalent log-analysis tools to detect and auto-block repeated authentication failures will reduce exposure to the observed brute-force patterns. Network operators should consider reaching out to OOO WestCall Ltd. to report the malicious activity and request investigation of the source infrastructure.