Active Threat β’ MEDIUM
163.245.221.134
Country of OriginπΊπΈ United States
First Detection3/31/2026
Last Activity4/1/2026
ISPInterserver, Inc
π―
334
Total Attacks
π
1
Ports
π‘
1
Attack Types
π¦
21
Malware
Geolocation
- Country
- πΊπΈ United States
- City
- Unknown
- ASN
- AS19318
- ISP
- Interserver, Inc
Attack Types
ssh_telnet_honeypot
Attacked Ports
22
Associated Malware
Attempted Credentials
π345gs5662d34/345gs5662d34
2xπroot/3245gs5662d34
2xπroot/rk@123456
1xπroot/oracle1
1xπroot/202531
1xπroot/7895123
1xπroot/Tr@123456
1xπroot/lin12345
1xπroot/p0o9i8u7
1xπroot/backup2025
1xπroot/password123456789
1xπroot/abah
1xπroot/jJ123456
1xπroot/password#123
1xπroot/Q!w2e3r4t5
1xExecuted Commands
$
lscpu | grep Model2x$
ls -lh $(which ls)2x$
cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'2x$
uname -a2x$
w2x$
cat /proc/cpuinfo | grep name | wc -l2x$
crontab -l2x$
cat /proc/cpuinfo | grep model | grep name | wc -l2x$
which ls2x$
uname2xShodan InternetDB ExposureShodan
InternetDB data, not real-time
Risk Assessment
55
/100
LowMediumHighCritical