172.214.45.193
Location
🇺🇸 US / Washington
ASN
AS8075 · Microsoft Corporation
Cloud Provider
Microsoft Azure
Total Events
604
Top 5% by volume
Agent Count
2
First / Last Seen
2026-02-24 15:27 — 2026-02-24 20:10
Attack Types
External Corroboration
Not flagged by any external feeds
Campaigns
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Session Forensics
Sessions
76 (74 with login)
Avg Depth Score
0.59
Commands Executed
76
Files Downloaded
0
Notable Commands
- grep 'model name' /proc/cpuinfo 2>/dev/null | head -1 | cut -d ':' -f2- | sed 's/^ *//' | xargs || echo unknown
- xargs
- uname -a
- netstat -tulpn | head -10
- hostname
- pwd
- mount | head -5
- ps aux | head -10
- ssh -V
- whoami
- nproc 2>/dev/null || (grep -c '^processor' /proc/cpuinfo 2>/dev/null) || echo 0
- grep -c ^processor /proc/cpuinfo 2 > /dev/null
- uname -m 2>/dev/null || echo unknown
- uptime
- history | tail -5
- ls -la /
- env | head -10
Fingerprints
HASSH
SSH Client
Recent Events (last 50)
| Timestamp | Port | Proto | Event | Location |
|---|---|---|---|---|
| 2026-02-24 20:10:01 | :22 | ssh | cowrie.session.closed | sin |
| 2026-02-24 20:10:01 | :22 | ssh | cowrie.log.closed | sin |
| 2026-02-24 20:10:01 | :22 | ssh | cowrie.command.failed | sin |
| 2026-02-24 20:10:01 | :22 | ssh | cowrie.command.input | sin |
| 2026-02-24 20:10:01 | :22 | ssh | cowrie.session.params | sin |
| 2026-02-24 20:10:01 | :22 | ssh | cowrie.login.success | sin |
| 2026-02-24 20:10:00 | :22 | ssh | cowrie.client.kex | sin |
| 2026-02-24 20:10:00 | :22 | ssh | cowrie.client.version | sin |
| 2026-02-24 20:10:00 | :22 | ssh | cowrie.session.connect | sin |
| 2026-02-24 20:08:32 | :22 | ssh | cowrie.session.closed | sea |
| 2026-02-24 20:08:32 | :22 | ssh | cowrie.log.closed | sea |
| 2026-02-24 20:08:32 | :22 | ssh | cowrie.command.input | sea |
| 2026-02-24 20:08:32 | :22 | ssh | cowrie.session.params | sea |
| 2026-02-24 20:08:32 | :22 | ssh | cowrie.login.success | sea |
| 2026-02-24 20:08:32 | :22 | ssh | cowrie.client.kex | sea |
| 2026-02-24 20:08:32 | :22 | ssh | cowrie.client.version | sea |
| 2026-02-24 20:08:32 | :22 | ssh | cowrie.session.connect | sea |
| 2026-02-24 20:02:20 | :22 | ssh | cowrie.session.closed | sin |
| 2026-02-24 20:02:20 | :22 | ssh | cowrie.log.closed | sin |
| 2026-02-24 20:02:20 | :22 | ssh | cowrie.command.input | sin |
| 2026-02-24 20:02:20 | :22 | ssh | cowrie.session.params | sin |
| 2026-02-24 20:02:20 | :22 | ssh | cowrie.login.success | sin |
| 2026-02-24 20:02:19 | :22 | ssh | cowrie.client.kex | sin |
| 2026-02-24 20:02:19 | :22 | ssh | cowrie.client.version | sin |
| 2026-02-24 20:02:19 | :22 | ssh | cowrie.session.connect | sin |
| 2026-02-24 20:00:53 | :22 | ssh | cowrie.session.closed | sea |
| 2026-02-24 20:00:53 | :22 | ssh | cowrie.log.closed | sea |
| 2026-02-24 20:00:53 | :22 | ssh | cowrie.command.input | sea |
| 2026-02-24 20:00:53 | :22 | ssh | cowrie.session.params | sea |
| 2026-02-24 20:00:53 | :22 | ssh | cowrie.login.success | sea |
| 2026-02-24 20:00:53 | :22 | ssh | cowrie.client.kex | sea |
| 2026-02-24 20:00:53 | :22 | ssh | cowrie.client.version | sea |
| 2026-02-24 20:00:53 | :22 | ssh | cowrie.session.connect | sea |
| 2026-02-24 19:54:43 | :22 | ssh | cowrie.session.closed | sin |
| 2026-02-24 19:54:43 | :22 | ssh | cowrie.log.closed | sin |
| 2026-02-24 19:54:43 | :22 | ssh | cowrie.command.input | sin |
| 2026-02-24 19:54:43 | :22 | ssh | cowrie.session.params | sin |
| 2026-02-24 19:54:43 | :22 | ssh | cowrie.login.success | sin |
| 2026-02-24 19:54:42 | :22 | ssh | cowrie.client.kex | sin |
| 2026-02-24 19:54:42 | :22 | ssh | cowrie.client.version | sin |
| 2026-02-24 19:54:42 | :22 | ssh | cowrie.session.connect | sin |
| 2026-02-24 19:53:14 | :22 | ssh | cowrie.session.closed | sea |
| 2026-02-24 19:53:14 | :22 | ssh | cowrie.log.closed | sea |
| 2026-02-24 19:53:14 | :22 | ssh | cowrie.command.input | sea |
| 2026-02-24 19:53:14 | :22 | ssh | cowrie.session.params | sea |
| 2026-02-24 19:53:14 | :22 | ssh | cowrie.login.success | sea |
| 2026-02-24 19:53:14 | :22 | ssh | cowrie.client.kex | sea |
| 2026-02-24 19:53:14 | :22 | ssh | cowrie.client.version | sea |
| 2026-02-24 19:53:14 | :22 | ssh | cowrie.session.connect | sea |
| 2026-02-24 19:47:11 | :22 | ssh | cowrie.session.closed | sin |