Substantial Risk
IP 3.131.220.121 is a high-risk address operating from Amazon Web Services infrastructure (AS16509, AMAZON-02) in the United States, associated with sustained automated intrusion attempts and listed hacking activity generating 1,306 total abuse reports with a 96% confidence score and an 8/10 activity frequency rating.
Detection data spanning February through May 2026 indicates 20 confirmed hacking-category incidents alongside a single exploited-host classification, all sourced from automated honeypot sensors distributed across multiple reporting nodes. The volume of reports suggests persistent, scripted probing behavior rather than isolated scanning, with the IP demonstrating continuous engagement against target services over a four-month observation window. Network attribution points to AWS infrastructure, meaning this address likely represents either a compromised cloud instance repurposed as an attack platform or an actor leveraging cloud resources for offensive operations.
The dominant hacking classification encompasses unauthorized access attempts and exploitation-oriented activity, with specific evidence of Redis-targeted probing patterns detected by Suricata intrusion-detection signatures. Redis databases exposed to the internet without authentication or network-level restrictions represent a critical attack surface, as threat actors leverage automated honeypot sensors to identify and compromise these instances for data exfiltration, cryptocurrency mining or use as a botnet node. An exploited-host classification indicates this IP may itself be a compromised system being weaponized without the operator's knowledge, compounding the risk profile.
Defensive measures should include immediate blocking or rate-limiting of traffic originating from this address at the network perimeter, implementing fail2ban or similar dynamic firewall rules to automate mitigation, and auditing any publicly accessible Redis instances to enforce strong authentication and bind exclusively to localhost. Organizations should also consider notifying AWS abuse teams given the exploited-host classification, and ensure all exposed services follow least-privilege access controls with continuous monitoring for anomalous connection patterns.