Check an IP Address, Domain Name, Subnet, or ASN
136.111.99.120 has a threat confidence score of 96%. This IP address from United States (AS396982, Google LLC) has been observed in 18 honeypot sessions targeting REDIS protocols. Detected attack patterns include redis structured application secret harvesting. First observed on March 30, 2026, most recently active April 23, 2026.
Identifies structured extraction of high-value application configuration and credential material from a Redis datastore. The behavior includes keyspace enumeration, targeted TYPE inspection across configuration namespaces (cloud, database, encryption, JWT, mail, payment, VCS), and direct GET/HGETALL retrieval of secrets, API keys, feature flags, internal URLs, and user cache objects. This tightly grouped pattern reflects deliberate application-layer reconnaissance and credential harvesting following access to a Redis instance, indicating high-confidence data exposure and likely compromise of associated services.