Active ThreatMEDIUM

185.196.8.62

Country of Origin🇨🇭 CH
First Detection1/15/2026
Last Activity1/15/2026
ISPGlobal-Data System IT Corporation
🎯
527
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
26
Malware

Geolocation

Country
🇨🇭 CH
City
Unknown
ASN
AS42624
ISP
Global-Data System IT Corporation

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐345gs5662d34/345gs5662d34
5x
🔐superview/Password123
1x
🔐kafka/P@ssw0rd@123
1x
🔐Administrator/Administrator!
1x
🔐webmaster/P@ssw0rd
1x
🔐sconsole/123456
1x
🔐mail/password123
1x
🔐sonarqube/sonarqube@1234
1x
🔐wlsadmin/wlsadmin2025
1x
🔐aruba/P@ssw0rd@123
1x
🔐sa/sa2026!
1x
🔐mobotix/mobotix123
1x
🔐daemon/daemon@1234
1x
🔐elasticsearch/elasticsearch@123
1x
🔐caddy/caddy!
1x

Executed Commands

$whoami5x
$df -h | head -n 2 | awk 'FNR == 2 {print $2;}'5x
$Enter new UNIX password: 5x
$uname -a5x
$lockr -ia .ssh5x
$top5x
$uname -m5x
$free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'5x
$w5x
$cd ~; chattr -ia .ssh; lockr -ia .ssh5x

Risk Assessment

55
/100
LowMediumHighCritical