← Back to feed

130.131.195.135

TAGGED MALICIOUS how we decide →
Threat Confidence
60%
Location
🇺🇸 US / Des Moines
ASN
AS8075 · Microsoft Corporation
Cloud Provider
Microsoft Azure
Total Events
1201
Top 5% by volume
Agent Count
1
First / Last Seen
2026-05-08 05:52 — 2026-05-08 09:05
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
External Corroboration
Blocklist.de
Reported 2026-05-09 02:00
blocklist_de:reported
Campaigns
Not associated with any campaigns
Session Forensics
malware_dropper ×46 credential_probe ×1
Sessions
47 (46 with login)
Avg Depth Score
0.98
Commands Executed
828
Files Downloaded
46
Notable Commands
  • echo "===HOSTNAME==="; hostname 2>/dev/null || echo EMPTY;; echo "===UNAME==="; uname -a 2>/dev/null || echo EMPTY;; echo "===WHOAMI==="; whoami 2>/dev/null || echo EMPTY;; echo "===PWD==="; pwd 2>/dev/null || echo EMPTY;; echo "===LS_ROOT==="; ls -la / 2>/dev/null | head -10 || echo EMPTY;; echo "===PS==="; ps aux 2>/dev/null | head -15 || echo EMPTY;; echo "===NETSTAT==="; netstat -tulpn 2>/dev/null | head -10 || echo EMPTY;; echo "===HISTORY==="; history 2>/dev/null | tail -5 || echo EMPTY;; echo "===SSH_VERSION==="; ssh -V 2>&1 || echo EMPTY;; echo "===UPTIME==="; uptime 2>/dev/null || echo EMPTY;; echo "===MOUNT==="; mount 2>/dev/null | head -5 || echo EMPTY;; echo "===ENV==="; env 2>/dev/null | head -10 || echo EMPTY;; echo "===CPU_CORES==="; nproc 2>/dev/null || grep -c '^processor' /proc/cpuinfo 2>/dev/null || echo 0;; echo "===ARCH==="; uname -m 2>/dev/null || echo unknown;; echo "===CPU_MODEL==="; grep 'model name' /proc/cpuinfo 2>/dev/null | head -1 | cut -d ':' -f2- | sed 's/^ *//' || echo unknown;; echo "===RESOURCES==="; echo MEMKB=$(awk '/MemTotal/{print $2}' /proc/meminfo 2>/dev/null) DISKKB=$(df / 2>/dev/null | awk 'NR==2{print $2}') USERCNT=$(wc -l < /etc/passwd 2>/dev/null) PKGCNT=$(dpkg -l 2>/dev/null | grep -c '^ii' || rpm -qa 2>/dev/null | wc -l || echo 0);; echo "===CONTAINER==="; cat /proc/1/cgroup 2>/dev/null | head -3; test -f /.dockerenv && echo DOCKERENV; test -f /run/.containerenv && echo CONTAINERENV; echo;; echo "===COWRIE==="; ls /opt/cowrie /home/richard /etc/cowrie 2>&1;; echo "===DMESG==="; dmesg 2>/dev/null | head -5 || echo EMPTY;; echo "===PORTS==="; ss -tulpn 2>/dev/null | grep LISTEN | head -20 || netstat -tulpn 2>/dev/null | grep LISTEN | head -20 || echo EMPTY;; echo "===NETCFG==="; ls -la /etc/network/interfaces /etc/sysconfig/network-scripts/ /etc/netplan/ 2>/dev/null | head -3 || echo EMPTY;; echo "===IPADDR==="; ip addr show 2>/dev/null | grep -E '^[0-9]+:' | head -5 || echo EMPTY;; echo "===IPROUTE==="; ip route show 2>/dev/null | head -3 || echo EMPTY;; echo "===WRITE==="; TF=/tmp/t_$$; echo test > $TF 2>&1 && echo WRITEOK && rm -f $TF || echo WRITEFAIL;; echo "===IDCHECK==="; id 2>/dev/null && echo IDOK || echo IDFAIL; whoami 2>/dev/null && echo WHOAMIOK || echo WHOAMIFAIL;; echo "===PKGMGR==="; which apt 2>/dev/null || which yum 2>/dev/null || which pacman 2>/dev/null || which zypper 2>/dev/null || echo NOPKG;; echo "===SERVICES==="; systemctl list-units --type=service --state=running 2>/dev/null | head -10 || echo NOSVC;; echo "===SOCKETS==="; ss -tuln 2>/dev/null | wc -l || echo 0;; echo "===GPU==="; nvidia-smi --query-gpu=name,memory.total,driver_version --format=csv,noheader 2>/dev/null || echo NOGPU;; echo "===MAXDISK==="; df -BG 2>/dev/null | awk 'NR>1{gsub("G","",$2); if($2+0>max) max=$2+0} END{print max+0}' || echo 0;; echo "===END==="
  • awk /MemTotal/{print $2} /proc/meminfo 2 > /dev/null
  • df / 2 > /dev/null | awk NR==2{print $2}
  • wc -l < /etc/passwd 2 > /dev/null
  • dpkg -l 2 > /dev/null | grep -c ^ii
  • dpkg -l
  • rpm -qa 2 > /dev/null | wc -l
  • rpm -qa
  • echo 0
  • sed s/^ *//
Fingerprints
SSH-2.0-Go
Evidence Timeline
Malware Dropper b3fac16e1fd8 w4m_seattle_01 · 2026-05-08 09:05
18 1 1 100%
Loading events...
Malware Dropper 49f3cadca2c6 w4m_seattle_01 · 2026-05-08 09:02
18 1 1 100%
Loading events...
Malware Dropper 00544f9bfb9d w4m_seattle_01 · 2026-05-08 08:58
18 1 1 100%
Loading events...
Malware Dropper cd66dc1a9c0b w4m_seattle_01 · 2026-05-08 08:54
18 1 1 100%
Loading events...
Malware Dropper 704a0809bfe9 w4m_seattle_01 · 2026-05-08 08:49
18 1 1 100%
Loading events...
Malware Dropper 38480b56254b w4m_seattle_01 · 2026-05-08 08:46
18 1 1 100%
Loading events...
Malware Dropper 8c3a3365306f w4m_seattle_01 · 2026-05-08 08:43
18 1 1 100%
Loading events...
Malware Dropper 8183ccf4abad w4m_seattle_01 · 2026-05-08 08:39
18 1 1 100%
Loading events...
Malware Dropper 7b35bf2f13d2 w4m_seattle_01 · 2026-05-08 08:34
18 1 1 100%
Loading events...
Malware Dropper dcf73307778a w4m_seattle_01 · 2026-05-08 08:30
18 1 1 100%
Loading events...
Malware Dropper 5a8496eebee6 w4m_seattle_01 · 2026-05-08 08:26
18 1 1 100%
Loading events...
Malware Dropper f57e580f0a09 w4m_seattle_01 · 2026-05-08 08:24
18 1 1 100%
Loading events...
Malware Dropper aa431dfeffd7 w4m_seattle_01 · 2026-05-08 08:20
18 1 1 100%
Loading events...
Malware Dropper 187cd2d54a1d w4m_seattle_01 · 2026-05-08 08:15
18 1 1 100%
Loading events...
Malware Dropper 58a5c4d878b3 w4m_seattle_01 · 2026-05-08 08:11
18 1 1 100%
Loading events...
Malware Dropper 1efd9c9dfbd7 w4m_seattle_01 · 2026-05-08 08:07
18 1 1 100%
Loading events...
Malware Dropper 5e6f6ce2fa11 w4m_seattle_01 · 2026-05-08 08:05
18 1 1 100%
Loading events...
Malware Dropper b677cae725c0 w4m_seattle_01 · 2026-05-08 08:01
18 1 1 100%
Loading events...
Malware Dropper 94a552de7035 w4m_seattle_01 · 2026-05-08 07:56
18 1 1 100%
Loading events...
Malware Dropper f24ea0363714 w4m_seattle_01 · 2026-05-08 07:51
18 1 1 100%
Loading events...
Malware Dropper e5323ae3470c w4m_seattle_01 · 2026-05-08 07:47
18 1 1 100%
Loading events...
Malware Dropper 10644347da4c w4m_seattle_01 · 2026-05-08 07:45
18 1 1 100%
Loading events...
Malware Dropper 2727a16b8291 w4m_seattle_01 · 2026-05-08 07:42
18 1 1 100%
Loading events...
Malware Dropper 72d9f6e474e6 w4m_seattle_01 · 2026-05-08 07:37
18 1 1 100%
Loading events...
Malware Dropper 2d7882e77b8c w4m_seattle_01 · 2026-05-08 07:32
18 1 1 100%
Loading events...
Malware Dropper 99905f71a65c w4m_seattle_01 · 2026-05-08 07:28
18 1 1 100%
Loading events...
Malware Dropper eedd59d2ce4e w4m_seattle_01 · 2026-05-08 07:26
18 1 1 100%
Loading events...
Malware Dropper 011f81e75e8e w4m_seattle_01 · 2026-05-08 07:22
18 1 1 100%
Loading events...
Malware Dropper e71c12b39336 w4m_seattle_01 · 2026-05-08 07:18
18 1 1 100%
Loading events...
Malware Dropper a6b59e3f4bb9 w4m_seattle_01 · 2026-05-08 07:13
18 1 1 100%
Loading events...
Malware Dropper 40d0c787306c w4m_seattle_01 · 2026-05-08 07:09
18 1 1 100%
Loading events...
Malware Dropper b2265c660e8a w4m_seattle_01 · 2026-05-08 07:07
18 1 1 100%
Loading events...
Malware Dropper 3b258d3d88e0 w4m_seattle_01 · 2026-05-08 07:03
18 1 1 100%
Loading events...
Malware Dropper cf5d3e0ec36f w4m_seattle_01 · 2026-05-08 06:59
18 1 1 100%
Loading events...
Malware Dropper 5b4aaae77659 w4m_seattle_01 · 2026-05-08 06:54
18 1 1 100%
Loading events...
Malware Dropper 0e090bc9a96b w4m_seattle_01 · 2026-05-08 06:50
18 1 1 100%
Loading events...
Malware Dropper 5f3fc8775ea1 w4m_seattle_01 · 2026-05-08 06:48
18 1 1 100%
Loading events...
Malware Dropper 3072dcf21fe1 w4m_seattle_01 · 2026-05-08 06:44
18 1 1 100%
Loading events...
Malware Dropper a319eceddc28 w4m_seattle_01 · 2026-05-08 06:39
18 1 1 100%
Loading events...
Malware Dropper f8d0a97454dc w4m_seattle_01 · 2026-05-08 06:35
18 1 1 100%
Loading events...
Malware Dropper 3a91a7df2182 w4m_seattle_01 · 2026-05-08 06:25
18 1 1 100%
Loading events...
Malware Dropper aac9d5487ac6 w4m_seattle_01 · 2026-05-08 06:20
18 1 1 100%
Loading events...
Malware Dropper 73bcda30df2d w4m_seattle_01 · 2026-05-08 06:16
18 1 1 100%
Loading events...
Malware Dropper e97b1b01a64c w4m_seattle_01 · 2026-05-08 06:06
18 1 1 100%
Loading events...
Malware Dropper 976e59cd258c w4m_seattle_01 · 2026-05-08 06:01
18 1 1 100%
Loading events...
Malware Dropper 207d56c5d431 w4m_seattle_01 · 2026-05-08 05:56
18 1 1 100%
Loading events...
Credential Probe 3ac9b40c56af w4m_seattle_01 · 2026-05-08 05:52
1 20%
Loading events...