← Back to feed
Location
🇨🇳 CN
ASN
AS38365 · Beijing Baidu Netcom Science and Technology Co., Ltd.
Cloud Provider
—
Total Events
79
Above average by volume
Agent Count
2
First / Last Seen
2026-04-07 19:58 — 2026-04-23 12:00
Attack Types
MITRE ATT&CK Techniques
Initial Access
External Corroboration
Blocklist.de
blocklist_de:reported
Campaigns
HASSH 03a80b21afa8… — SSH-2.0-libssh_0.11.1 (536 IPs, 67 countries)
HASSH
Active
high
🇨🇳 CN
536 IPs
196305 events
ssh:bruteforce
2026-02-27 — ongoing · 536 IPs are running an identical SSH client (HASSH fingerprint 03a80b21afa8…). Top network: China Telecom Group (AS4811). Geographic …
AS38365 Beijing Baidu Netcom Science and Technology Co., Ltd.
ASN
Active
medium
🇨🇳 CN
36 IPs
1768 events
ssh:bruteforce
2026-02-18 — ongoing · 36 IPs from the same network (Beijing Baidu Netcom Science and Technology Co., Ltd., AS38365) were active during …
Session Forensics
Sessions
19 (2 with login)
Avg Depth Score
0.2
Commands Executed
2
Files Downloaded
0
Notable Commands
- cd ~; chattr -ia .ssh; lockr -ia .ssh
- lockr -ia .ssh
Fingerprints
HASSH
SSH Client
Evidence Timeline
Scanner
914a7d6b6d1d
15%
Loading events...
SSH-2.0-libssh_0.11.1
Scanner
af42ee042158
15%
Loading events...
SSH-2.0-libssh_0.11.1
Opportunistic Bruter
0eafd35346db
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
c7c82c8565c4
15%
Loading events...
Reconnaissance
0da56811931a
LOGIN
2
1
60%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh
Scanner
6bc6d49b861c
15%
Loading events...