High Risk
IP 165.227.110.45 is a high-risk address associated with persistent hacking activity and classified as an exploited host, presenting a threat level of 8/10 based on 2027 reported incidents detected by automated honeypot sensors over approximately ten months.
The detection data reveals sustained malicious operations originating from this DigitalOcean-registered IP within AS14061 in the United States. With 2027 total reports and an activity frequency rating of 8/10, the address demonstrates consistent offensive behavior across multiple honeypot sensors, all of which confirmed the same attack patterns. The reported activity spans from September 2025 through July 2026, indicating prolonged involvement in hostile network operations rather than isolated probing. Community reporting and automated honeypot sensors jointly identified the address as a source of database-targeting attacks, with specific patterns pointing to Redis exploitation techniques commonly used to compromise improperly secured NoSQL installations.
The dominant threat category of hacking activity combined with the Redis attack pattern represents a concrete risk to exposed database services lacking proper authentication and network segmentation. Redis exploitation allows threat actors to execute arbitrary commands, access sensitive data, or leverage the compromised host for further network intrusion. The classification as an exploited host suggests this IP may itself be a compromised cloud instance weaponized without the owner's knowledge, a common occurrence in shared hosting environments where attackers compromise weak configurations to establish persistent attack infrastructure. This dual characterization amplifies the real-world danger, as blocking the address provides only temporary mitigation while the underlying compromised system remains a potential resource for future campaigns.
Site operators should immediately block IP 165.227.110.45 at network perimeter devices and web application firewalls to prevent reconnaissance and connection attempts. Exposed Redis instances should enforce strong authentication, bind to localhost only, and disable dangerous commands to prevent exploitation. Implementing fail2ban or similar intrusion prevention tools can automatically block repeated attack patterns. Regular monitoring of authentication logs and network traffic for connection attempts from known malicious addresses will strengthen defensive posture against this and similar threat sources.