Substantial Risk
IP 207.90.244.27 is a high-risk address operating from Cogent Communications infrastructure in the United States, linked to widespread brute-force and exploitation activity with an 8/10 threat level and over 11,000 abuse reports submitted through automated honeypot sensors and community sources since September 2025.
Detection data shows 21 distinct threat incidents attributed to this IP across the reporting period, with Hacking activity accounting for the overwhelming majority of recent submissions. The IP demonstrates a persistent 8/10 activity frequency, indicating continuous automated scanning and attack propagation rather than isolated incidents. Community reports and honeypot telemetry reveal consistent patterns targeting Redis database services with authentication bypass attempts, probing web application honeypots designed to simulate vulnerable endpoints, and generating SMTP abuse through spam relay and enumeration techniques. The AS174 network allocation through Cogent Communications places this source within a major North American backbone provider, suggesting the originating system may be part of a compromised infrastructure cluster or a dedicated attack platform.
The dominant Hacking classification encompasses the observed Redis exploitation attempts and general intrusion activity, representing a concrete threat to any exposed Redis deployments accepting unauthenticated or weakly secured connections. Redis attack patterns frequently precede data exfiltration, cryptocurrency mining deployment, or lateral movement within cloud-native environments where Redis runs without network segmentation. Combined with SMTP abuse capabilities, this IP presents a multi-vector risk capable of supporting both direct compromise campaigns and downstream spam distribution networks, amplifying its potential impact across internet-facing services.
Site operators should block 207.90.244.27 at the network perimeter and implement fail2ban or equivalent rate-limiting rules to mitigate repeated authentication attempts. Redis instances should enforce strong authentication, bind to localhost only, and disable dangerous commands to prevent exploitation even if network access is inadvertently exposed. Web application firewalls and intrusion detection systems should log and alert on the observed attack signatures, while regular security audits of externally facing services reduce the attack surface available to automated scanners operating from this address.