Active Threat β’ MEDIUM
52.5.16.170
Country of OriginπΊπΈ United States
First Detection5/2/2026
Last Activity5/3/2026
ISPAmazon.com, Inc.
π―
58
Total Attacks
π
1
Ports
π‘
1
Attack Types
π¦
4
Malware
Geolocation
- Country
- πΊπΈ United States
- City
- Ashburn
- ASN
- AS14618
- ISP
- Amazon.com, Inc.
Attack Types
ssh_telnet_honeypot
Attacked Ports
22
Associated Malware
Attempted Credentials
πroot/password
4xπroot/root
2xπroot/123456
2xπroot/toor
2xπroot/(empty)
2xExecuted Commands
$
nohup /tmp/.sorry_Zn5PUpZ3 >/tmp/.sorry_hRn9AMY7.log 2>&1 &1x$
chmod +x /tmp/.sorry_Zn5PUpZ31xShodan InternetDB ExposureShodan
InternetDB data, not real-time
Ports
80443
Hostnames
gilpinrealty.comwww.gilpinrealty.comec2-52-5-16-170.compute-1.amazonaws.com
CPEs
cpe:/a:mysql:mysqlcpe:/a:litespeedtech:litespeed_web_servercpe:/a:php:phpcpe:/a:wordpress:wordpress
Risk Assessment
45
/100
LowMediumHighCritical