Active Threat β’ HIGH
173.10.13.18
Country of OriginπΊπΈ United States
First Detection3/26/2026
Last Activity3/31/2026
ISPComcast Cable Communications, LLC
π―
281
Total Attacks
π
1
Ports
π‘
1
Attack Types
π¦
24
Malware
Geolocation
- Country
- πΊπΈ United States
- City
- Stockton
- ASN
- AS7922
- ISP
- Comcast Cable Communications, LLC
Attack Types
ssh_telnet_honeypot
Attacked Ports
22
Associated Malware
Attempted Credentials
π345gs5662d34/345gs5662d34
3xπroot/Abc123456789
1xπautomation/3245gs5662d34
1xπali/3245gs5662d34
1xπroot/1234.abcd
1xπroot/A123456*
1xπroot/3245gs5662d34
1xπroot/zjidc.com
1xπroot/Izhenqi(!@#)2025
1xπautomation/123456
1xπroot/webadmin123456!@#$%^
1xπroot/kef111777
1xπroot/idc2001
1xπemo/1234
1xπmailtest/mailtest1234
1xExecuted Commands
$
Enter new UNIX password:4x$
lscpu | grep Model3x$
ls -lh $(which ls)3x$
cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'3x$
uname -a3x$
w3x$
cat /proc/cpuinfo | grep name | wc -l3x$
crontab -l3x$
cat /proc/cpuinfo | grep model | grep name | wc -l3x$
which ls3xShodan InternetDB ExposureShodan
InternetDB data, not real-time
Ports
25531101439951000020000
Hostnames
173-10-13-18-BusName-stockton.hfc.comcastbusiness.net
CPEs
cpe:/a:postfix:postfixcpe:/a:webmin:webmin
Risk Assessment
62
/100
LowMediumHighCritical