Notable Threat
IP 207.90.244.25 is a high-risk address with a threat level of 8 out of 10 that has generated 13,682 abuse reports from automated honeypot sensors, making it one of the most persistently reported IPs in recent months. The dominant activity associated with this Cogent Communications-hosted address involves repeated hacking attempts including Redis-targeted attacks and broader malware or exploit activity targeting exposed services.
The volume of reports is exceptionally high, with 20 distinct threat-category submissions logged across the reporting period from September 2025 through June 2026. All confirmed detections originated from automated honeypot sensors, indicating that the observed activity represents automated scanning and exploitation attempts rather than isolated manual intrusion attempts. The activity frequency rating of 8 out of 10 further corroborates that this IP maintains a continuous, high-volume assault posture against internet-facing infrastructure. Operating within AS174 (Cogent Communications) and geolocated in the United States, this address presents a well-connected threat vector capable of reaching a broad range of potential targets globally.
The reported threat categories reveal a dual risk profile. The "Hacking" classification encompasses general intrusion attempts, vulnerability exploitation and unauthorized access attempts against exposed services. The "Exploited Host" classification indicates that activity patterns are consistent with a compromised system being weaponized as an unwitting attack platform. The specific attack patterns observed—particularly Redis-directed attacks—suggest the IP is actively probing for misconfigured in-memory data stores to exploit, while broader malware and exploit activity indicates horizontal scanning for multiple vulnerability classes. An IP with this report volume and diversity of attack vectors poses a concrete risk to any organization running unpatched or poorly hardened internet-facing services.
Site operators should block or heavily rate-limit traffic from 207.90.244.25 at the network perimeter firewall or web application firewall layer. Implementing authentication hardening on all exposed services—enforcing strong credentials, disabling default administrative interfaces and applying multi-factor authentication—reduces the likelihood of successful compromise. Deploying intrusion detection signatures and configuring automated response tools such as fail2ban can help identify and neutralize repeated connection attempts in real time. Finally, monitoring for the specific attack patterns associated with this address in network logs enables rapid triage if any probing activity slips through perimeter defenses.