Active ThreatHIGH

34.128.77.56

Country of Origin🇮🇩 Indonesia
First Detection1/21/2026
Last Activity1/24/2026
ISPGOOGLE-CLOUD-PLATFORM
🎯
1313
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
28
Malware

Geolocation

Country
🇮🇩 Indonesia
City
Jakarta
ASN
AS396982
ISP
GOOGLE-CLOUD-PLATFORM

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐345gs5662d34/345gs5662d34
6x
🔐root/root
3x
🔐msf/123456
1x
🔐sir/sir2025
1x
🔐amsftp/123456
1x
🔐liu/123
1x
🔐elastic/password
1x
🔐alumno/alumno2025
1x
🔐superuser/superuser123!
1x
🔐informix/123
1x
🔐vnc/123
1x
🔐vncuser/vncuser2025
1x
🔐bitch/123456
1x
🔐spa/spa@123
1x
🔐elsearch/elsearch123
1x

Executed Commands

$cd ~; chattr -ia .ssh; lockr -ia .ssh6x
$lscpu | grep Model6x
$w6x
$crontab -l6x
$cat /proc/cpuinfo | grep model | grep name | wc -l6x
$which ls6x
$Enter new UNIX password:6x
$uname6x
$whoami6x
$df -h | head -n 2 | awk 'FNR == 2 {print $2;}'6x

Risk Assessment

60
/100
LowMediumHighCritical