← Back to feed
172.174.223.102
Location
🇺🇸 US / Washington
ASN
AS8075 · Microsoft Corporation
Cloud Provider
Microsoft Azure
Total Events
652
Top 5% by volume
Agent Count
1
First / Last Seen
2026-04-06 13:51 — 2026-04-06 19:18
Attack Types
MITRE ATT&CK Techniques
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
Sessions
81 (81 with login)
Avg Depth Score
0.6
Commands Executed
85
Files Downloaded
0
Notable Commands
- hostname
- ps aux | head -10
- uname -m 2>/dev/null || echo unknown
- env | head -10
- ls -la /
- netstat -tulpn | head -10
- nproc 2>/dev/null || (grep -c '^processor' /proc/cpuinfo 2>/dev/null) || echo 0
- grep -c ^processor /proc/cpuinfo 2 > /dev/null
- uname -a
- ssh -V
- pwd
- history | tail -5
- whoami
- grep 'model name' /proc/cpuinfo 2>/dev/null | head -1 | cut -d ':' -f2- | sed 's/^ *//' | xargs || echo unknown
- xargs
- mount | head -5
- uptime
Fingerprints
HASSH
SSH Client
Evidence Timeline
Reconnaissance
2dd3fc0cf5d5
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
c77750f91d49
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ps aux | head -10
Reconnaissance
1b0d76d81899
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -m 2>/dev/null || echo unknown
Reconnaissance
ae901adc7e0f
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ env | head -10
Reconnaissance
287fa2a0c868
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
abdb0d9cc425
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ netstat -tulpn | head -10
Reconnaissance
21ecd9e3c966
LOGIN
2
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ nproc 2>/dev/null || (grep -c '^processor' /proc/cpuinfo 2>…$ grep -c ^processor /proc/cpuinfo 2 > /dev/null
Reconnaissance
7298de121642
LOGIN
2
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ nproc 2>/dev/null || (grep -c '^processor' /proc/cpuinfo 2>…$ grep -c ^processor /proc/cpuinfo 2 > /dev/null
Reconnaissance
af5a04991f52
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
4b91522bb89c
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ssh -V
Reconnaissance
a3398db9de0a
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ pwd
Reconnaissance
8a2fb42ea75f
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ps aux | head -10
Reconnaissance
d3c1886d552c
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ps aux | head -10
Reconnaissance
938abeb5ee1d
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ netstat -tulpn | head -10
Reconnaissance
fe86033dc949
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
77dc9f3d6360
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
8c29956bb090
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
4072fda05749
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ pwd
Reconnaissance
6ee5577c3f4f
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ history | tail -5
Reconnaissance
af2b38b54321
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ssh -V
Reconnaissance
6d59a4e8cf93
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ whoami
Reconnaissance
a5a72acbf7cc
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ pwd
Reconnaissance
c2ee4281018c
LOGIN
2
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ grep 'model name' /proc/cpuinfo 2>/dev/null | head -1 | cut…$ xargs
Reconnaissance
4790f58872f3
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
056c46b1f2f0
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ pwd
Reconnaissance
de2827315f3a
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ netstat -tulpn | head -10
Reconnaissance
681461dcca3f
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ whoami
Reconnaissance
ff9b76b8d473
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
e6c9a2428771
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
42b67ea999a9
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
b55c73f900ba
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
4f8edde58380
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
3a4a1cc82af3
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
514034dd6458
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ mount | head -5
Reconnaissance
7c27ac684a13
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uptime
Reconnaissance
23ef12a0387a
LOGIN
2
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ grep 'model name' /proc/cpuinfo 2>/dev/null | head -1 | cut…$ xargs
Reconnaissance
595513a29fe8
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ mount | head -5
Reconnaissance
21e37130b769
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ history | tail -5
Reconnaissance
9e5554015448
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
b1335b47b647
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
0fb816c4b961
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
c5021d2a58dc
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
1210ad7fc2c7
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ mount | head -5
Reconnaissance
f9a0ede7490c
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
e485c663b207
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
07ddde7e8b36
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
74bbb9e9724a
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
f5ccd9e850a6
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
0d9733f86b24
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
17d7d43e91e9
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ netstat -tulpn | head -10