Active Threat β’ MEDIUM
104.236.144.123
Country of OriginπΊπΈ United States
First Detection4/27/2026
Last Activity4/27/2026
ISPDigitalOcean, LLC
π―
162
Total Attacks
π
1
Ports
π‘
1
Attack Types
π¦
18
Malware
Geolocation
- Country
- πΊπΈ United States
- City
- San Francisco
- ASN
- AS14061
- ISP
- DigitalOcean, LLC
Attack Types
ssh_telnet_honeypot
Attacked Ports
22
Associated Malware
Attempted Credentials
πroot/8522
1xπroot/Admin@2024.
1xπroot/qwerty@1234
1xπroot/Da123456.
1xπroot/admin_888
1xπroot/admin888.
1xπroot/3245gs5662d34
1xπroot/lalalala
1xπroot/wsad123
1xπroot/dubin@20240120
1xπroot/Rj123456
1xπroot/signature
1xπroot/zaq1xsw2CDE#
1xπroot/erty
1xπroot/P@ssw0rd111
1xExecuted Commands
$
lscpu | grep Model1x$
ls -lh $(which ls)1x$
cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'1x$
uname -a1x$
cat /proc/cpuinfo | grep name | wc -l1x$
crontab -l1x$
cat /proc/cpuinfo | grep model | grep name | wc -l1x$
uname1x$
whoami1x$
df -h | head -n 2 | awk 'FNR == 2 {print $2;}'1xShodan InternetDB ExposureShodan
InternetDB data, not real-time
Ports
808383
Vulnerabilities
CVE-2021-3618CVE-2017-20005CVE-2018-16845CVE-2019-9516CVE-2019-9511CVE-2021-23017CVE-2019-20372CVE-2018-16844CVE-2025-23419CVE-2018-16843CVE-2023-44487CVE-2019-9513
CPEs
cpe:/a:openbsd:openssh:6.6.1p1cpe:/a:phusionpassenger:phusion_passenger:5.2.0cpe:/o:canonical:ubuntu_linuxcpe:/a:jquery:jquerycpe:/a:f5:nginx:1.12.2cpe:/a:getbootstrap:bootstrap:1.13.9cpe:/a:datatables:datatables.netcpe:/a:ruby-lang:rubycpe:/a:rubyonrails:rails
Risk Assessment
55
/100
LowMediumHighCritical