Active Threat • HIGH
103.27.36.2
Country of Origin🇮🇩 Indonesia
First Detection3/26/2026
Last Activity4/26/2026
ISPPT Aseli Dagadu Djokdja
🎯
380
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
23
Malware
Geolocation
- Country
- 🇮🇩 Indonesia
- City
- Unknown
- ASN
- AS132670
- ISP
- PT Aseli Dagadu Djokdja
Attack Types
ssh_telnet_honeypot
Attacked Ports
22
Associated Malware
Attempted Credentials
🔐345gs5662d34/345gs5662d34
2x🔐root/3245gs5662d34
2x🔐root/sp123456
1x🔐root/q!w2e3r4t5y6
1x🔐root/keleman;7
1x🔐root/mostrador
1x🔐root/p@$$word!
1x🔐root/!qa2ws3ed4rf5tg
1x🔐root/1997
1x🔐root/111999
1x🔐root/w3lc0me
1x🔐root/!qaz2xsw3edc
1x🔐root/nurse
1x🔐root/pass.111
1x🔐root/ABC123!
1xExecuted Commands
$
cd ~; chattr -ia .ssh; lockr -ia .ssh2x$
ls -lh $(which ls)2x$
cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'2x$
uname -a2x$
w2x$
cat /proc/cpuinfo | grep name | wc -l2x$
crontab -l2x$
cat /proc/cpuinfo | grep model | grep name | wc -l2x$
which ls2x$
uname2xShodan InternetDB ExposureShodan
InternetDB data, not real-time
Ports
53161170117232000
Hostnames
103-27-36-2.dagadu.co.id
Risk Assessment
65
/100
LowMediumHighCritical