Active Threat β’ HIGH
167.99.68.185
Country of OriginπΈπ¬ Singapore
First Detection3/14/2026
Last Activity3/18/2026
ISPDigitalOcean, LLC
π―
221
Total Attacks
π
1
Ports
π‘
1
Attack Types
π¦
21
Malware
Geolocation
- Country
- πΈπ¬ Singapore
- City
- Singapore
- ASN
- AS14061
- ISP
- DigitalOcean, LLC
Attack Types
ssh_telnet_honeypot
Attacked Ports
22
Associated Malware
Attempted Credentials
π345gs5662d34/345gs5662d34
2xπguillaume/Guillaume123
1xπshadow/shadow123!
1xπmd/md1234
1xπzhuge/12345
1xπtigergraph/3245gs5662d34
1xπandroid/123456
1xπociispth/ociispth1234
1xπubuntuuser/ubuntuuser123
1xπdeployer/deployer
1xπuser02/12345678
1xπbert/Bert123!
1xπsav/3245gs5662d34
1xπmarek/Marek123!
1xπsav/Sav123!
1xExecuted Commands
$
Enter new UNIX password:4x$
cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'2x$
uname -a2x$
cd ~; chattr -ia .ssh; lockr -ia .ssh2x$
w2x$
which ls2x$
whoami2x$
lockr -ia .ssh2x$
uname -m2x$
lscpu | grep Model2xShodan InternetDB ExposureShodan
InternetDB data, not real-time
Ports
2263180018080
Vulnerabilities
CVE-2023-44487CVE-2025-23419
CPEs
cpe:/o:canonical:ubuntu_linuxcpe:/a:getbootstrap:bootstrapcpe:/a:f5:nginx:1.24.0cpe:/a:openbsd:openssh:9.6p1cpe:/o:linux:linux_kernel
Risk Assessment
62
/100
LowMediumHighCritical