Check an IP Address, Domain Name, Subnet, or ASN
162.133.143.106 has a threat confidence score of 98%. This IP address from United States (AS36351, IBM Cloud) has been observed in 24 honeypot sessions targeting REDIS protocols. Detected attack patterns include redis cron persistence multi variant payload. First observed on February 26, 2026, most recently active February 26, 2026.
Detects Redis configuration abuse where an exposed instance is reconfigured to write cron entries that execute remote payloads via curl or wget/variant binaries (including root-executed variants), followed by SAVE to persist the malicious cron file to disk. Covers multiple backup job names and pipe-to-shell download techniques used for automated persistence and recurring remote code execution.