Active Threat • HIGH
45.249.246.120
Country of Origin🇭🇰 Hong Kong
First Detection3/21/2026
Last Activity4/5/2026
ISPUCLOUD INFORMATION TECHNOLOGY HK LIMITED
🎯
964
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
35
Malware
Geolocation
- Country
- 🇭🇰 Hong Kong
- City
- Hong Kong
- ASN
- AS135377
- ISP
- UCLOUD INFORMATION TECHNOLOGY HK LIMITED
Attack Types
ssh_telnet_honeypot
Attacked Ports
22
Associated Malware
Attempted Credentials
🔐345gs5662d34/345gs5662d34
9x🔐root/3245gs5662d34
2x🔐sky/sky123
1x🔐samuel/3245gs5662d34
1x🔐lorenzo/123
1x🔐root/cns
1x🔐postgres/zaq1xsw2cde3vfr4
1x🔐sd/3245gs5662d34
1x🔐root/Qwer@2025
1x🔐root/abc123$%
1x🔐root/Cloud@2025
1x🔐admin2/admin2
1x🔐root/!@#123
1x🔐root/Root111111#
1x🔐hl/Hl123
1xExecuted Commands
$
Enter new UNIX password:14x$
cd ~; chattr -ia .ssh; lockr -ia .ssh9x$
ls -lh $(which ls)9x$
cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'9x$
uname -a9x$
w9x$
cat /proc/cpuinfo | grep name | wc -l9x$
crontab -l9x$
cat /proc/cpuinfo | grep model | grep name | wc -l9x$
which ls9xShodan InternetDB ExposureShodan
InternetDB data, not real-time
Ports
15588
Hostnames
urgijet.cn
Risk Assessment
65
/100
LowMediumHighCritical