Active ThreatHIGH

103.181.143.99

Country of Origin🇮🇩 Indonesia
First Detection1/9/2026
Last Activity1/11/2026
ISPPT Cloud Hosting Indonesia
🎯
653
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
26
Malware

Geolocation

Country
🇮🇩 Indonesia
City
Unknown
ASN
AS136052
ISP
PT Cloud Hosting Indonesia

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐345gs5662d34/345gs5662d34
5x
🔐root/nPSpP4PBW0
2x
🔐vpn/1212
1x
🔐ftpuser/3245gs5662d34
1x
🔐server/aa123456
1x
🔐test1/P@ssword123
1x
🔐user2/Abcd@2026
1x
🔐ubuntu/password
1x
🔐user1/admin
1x
🔐admin/Aa1234
1x
🔐root/666666
1x
🔐user/P@ssword1
1x
🔐test/test1
1x
🔐root/55555
1x
🔐claude/plunga471
1x

Executed Commands

$top5x
$crontab -l5x
$lscpu | grep Model5x
$w5x
$uname -m5x
$uname5x
$whoami5x
$free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'5x
$cat /proc/cpuinfo | grep name | wc -l5x
$cd ~; chattr -ia .ssh; lockr -ia .ssh5x

Risk Assessment

60
/100
LowMediumHighCritical
IP 103.181.143.99 - Detected Threat | TroyanosYVirus.com | TroyanosYVirus.com