Check an IP Address, Domain Name, Subnet, or ASN
34.9.214.80 has a very high threat confidence level of 97%, originating from Council Bluffs, United States, on the Google LLC network (396982). It has been observed across 44 sessions targeting REDIS, with detected attack patterns including redis structured application secret harvesting, First observed on February 15, 2026, most recently active March 11, 2026.
Identifies structured extraction of high-value application configuration and credential material from a Redis datastore. The behavior includes keyspace enumeration, targeted TYPE inspection across configuration namespaces (cloud, database, encryption, JWT, mail, payment, VCS), and direct GET/HGETALL retrieval of secrets, API keys, feature flags, internal URLs, and user cache objects. This tightly grouped pattern reflects deliberate application-layer reconnaissance and credential harvesting following access to a Redis instance, indicating high-confidence data exposure and likely compromise of associated services.