← Back to feed

138.99.79.29

TAGGED MALICIOUS how we decide →
Threat Confidence
64%
Location
🇧🇷 BR / Flores da Cunha
ASN
AS264157 · GUAREZE FIBRA LTDA
Cloud Provider
Total Events
25
Average by volume
Agent Count
2
First / Last Seen
2026-06-01 00:51 — 2026-06-01 01:41
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Initial Access
Execution
Credential Access
External Corroboration
Blocklist.de
Reported 2026-06-01 04:02
blocklist_de:reported
DShield Top Attackers
Reported 2026-06-01 04:01
dshield:top_attacker
Session Forensics
interactive_operator ×3
Sessions
3 (3 with login)
Avg Depth Score
0.9
Commands Executed
17
Files Downloaded
0
Notable Commands
  • if [ -r /proc/cpuinfo ] && [ -r /proc/meminfo ] && grep -q "model name" /proc/cpuinfo 2>/dev/null && grep -q "MemTotal" /proc/meminfo 2>/dev/null; then; echo "valid"; else; echo "honeypot"; fi
  • if [ -r /proc/cpuinfo ]
  • then
  • else
  • fi
  • [ -r /proc/meminfo ]
Fingerprints
SSH-2.0-Go
Evidence Timeline
Interactive Operator 532f6b25a3bb newark_01 · 2026-06-01 01:41
5 1 90%
Loading events...
Interactive Operator ac98b2fc5d25 w4m_singapore_01 · 2026-06-01 00:51
6 1 90%
Loading events...
Interactive Operator 297afd919b1c w4m_singapore_01 · 2026-05-31 19:45
6 1 90%
Loading events...