Active Threat β’ HIGH
189.4.4.85
Country of Originπ§π· Brazil
First Detection1/13/2026
Last Activity1/14/2026
ISPClaro NXT Telecomunicacoes Ltda
π―
835
Total Attacks
π
1
Ports
π‘
1
Attack Types
π¦
33
Malware
Geolocation
- Country
- π§π· Brazil
- City
- AraucΓ‘ria
- ASN
- AS28573
- ISP
- Claro NXT Telecomunicacoes Ltda
Attack Types
cowrie
Attacked Ports
22
Associated Malware
Attempted Credentials
π345gs5662d34/345gs5662d34
8xπvps/vps123!
1xπhp/123
1xπsage/1
1xπdownload/download
1xπmariadb/Password123
1xπliberty/liberty2026
1xπpeoplesoft/Password1
1xπclickhouse/clickhouse2025!
1xπcloud/12345678
1xπreadonly/readonly2025!
1xπmail/mail@1234
1xπcarel/carel2026
1xπAdministrator/Wonderware
1xπftpuser/ZYPCOM
1xExecuted Commands
$
cd ~; chattr -ia .ssh; lockr -ia .ssh8x$
ls -lh $(which ls)8x$
cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'8x$
Enter new UNIX password: 8x$
uname -a8x$
w8x$
cat /proc/cpuinfo | grep name | wc -l8x$
crontab -l8x$
cat /proc/cpuinfo | grep model | grep name | wc -l8x$
which ls8xRisk Assessment
60
/100
LowMediumHighCritical