Active Threat β€’ HIGH

154.221.28.214

First Detection2/6/2026
Last Activity2/22/2026
ISPOVH SAS
🎯
1040
Total Attacks
πŸ”Œ
1
Ports
πŸ“‘
1
Attack Types
🦠
32
Malware

Geolocation

Country
πŸ‡ΈπŸ‡¬ Singapore
City
Unknown
ASN
AS16276
ISP
OVH SAS

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

πŸ”345gs5662d34/345gs5662d34
8x
πŸ”test1/abc123
1x
πŸ”username/12345
1x
πŸ”root/aa-123456
1x
πŸ”mp/mp
1x
πŸ”claude/claude123
1x
πŸ”jan/jan123
1x
πŸ”git/Test@123
1x
πŸ”database/database
1x
πŸ”superuser/superuser123456
1x
πŸ”ansible-user/123456
1x
πŸ”piyush/123456
1x
πŸ”hamza/hamza@2024
1x
πŸ”root/pa$$W0rd
1x
πŸ”hunter/hunter@123
1x

Executed Commands

$Enter new UNIX password:14x
$df -h | head -n 2 | awk 'FNR == 2 {print $2;}'8x
$top8x
$uname8x
$w8x
$lockr -ia .ssh8x
$cat /proc/cpuinfo | grep name | wc -l7x
$lscpu | grep Model7x
$cat /proc/cpuinfo | grep model | grep name | wc -l7x
$cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'7x

Risk Assessment

65
/100
LowMediumHighCritical