Active Threat β’ MEDIUM
102.210.149.236
π―
173
Total Attacks
π
1
Ports
π‘
1
Attack Types
π¦
20
Malware
Geolocation
- Country
- πΏπ¦ South Africa
- City
- Johannesburg
- ASN
- AS328847
- ISP
- KoTDA
Attack Types
ssh_telnet_honeypot
Attacked Ports
22
Associated Malware
Attempted Credentials
πdeploy/frappe22
1xπroot/bt123456.
1xπroot/AAaa112233
1xπubuntu/123456qq
1xπtest/adipan123
1xπroot/Master2025
1xπftpuser/Ftpuser1
1xπjb/123..0
1xπroot/master123!
1xπroot/Admin2025#$
1xπroot/3245gs5662d34
1xπroot/xxAA111
1xπvnc/test123
1xπubuntu/Hello@1234
1xπroot/ccQQ123
1xExecuted Commands
$
lscpu | grep Model1x$
ls -lh $(which ls)1x$
cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'1x$
uname -a1x$
w1x$
cat /proc/cpuinfo | grep name | wc -l1x$
crontab -l1x$
cat /proc/cpuinfo | grep model | grep name | wc -l1x$
which ls1x$
uname1xShodan InternetDB ExposureShodan
InternetDB data, not real-time
Ports
53804434022404040634064410341174150415741598443
Vulnerabilities
CVE-2021-3618CVE-2025-23419CVE-2021-23017CVE-2023-44487
Hostnames
homabay-taifacare.dha.go.ke
CPEs
cpe:/a:jquery:jquery:3.5.1cpe:/o:canonical:ubuntu_linuxcpe:/a:f5:nginxcpe:/a:getbootstrap:bootstrapcpe:/a:f5:nginx:1.18.0cpe:/o:linux:linux_kernel
Risk Assessment
55
/100
LowMediumHighCritical