← Back to feed
172.214.47.38
Location
🇺🇸 US / Washington
ASN
AS8075 · Microsoft Corporation
Cloud Provider
Microsoft Azure
Total Events
941
Top 5% by volume
Agent Count
1
First / Last Seen
2026-04-10 17:37 — 2026-04-10 23:08
Attack Types
MITRE ATT&CK Techniques
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
Sessions
117 (100 with login)
Avg Depth Score
0.6
Commands Executed
105
Files Downloaded
0
Notable Commands
- whoami
- uname -m 2>/dev/null || echo unknown
- history | tail -5
- netstat -tulpn | head -10
- env | head -10
- uptime
- hostname
- uname -a
- grep 'model name' /proc/cpuinfo 2>/dev/null | head -1 | cut -d ':' -f2- | sed 's/^ *//' | xargs || echo unknown
- xargs
- ls -la /
- ps aux | head -10
- nproc 2>/dev/null || (grep -c '^processor' /proc/cpuinfo 2>/dev/null) || echo 0
- grep -c ^processor /proc/cpuinfo 2 > /dev/null
- mount | head -5
- ssh -V
- pwd
Fingerprints
HASSH
SSH Client
Evidence Timeline
Reconnaissance
2131b861e7fc
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ whoami
Reconnaissance
7756c873870e
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -m 2>/dev/null || echo unknown
Reconnaissance
2dab80ee74e9
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ history | tail -5
Reconnaissance
85fbdb5c3cf0
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ netstat -tulpn | head -10
Reconnaissance
77370e21a8ad
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ env | head -10
Reconnaissance
0f0f458a86e8
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uptime
Reconnaissance
72f713a16de6
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ history | tail -5
Reconnaissance
86841257d0be
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
4dc940836881
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ whoami
Reconnaissance
bcb76fd75a55
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ netstat -tulpn | head -10
Reconnaissance
6dc4f8014891
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
a149cd04e923
LOGIN
2
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ grep 'model name' /proc/cpuinfo 2>/dev/null | head -1 | cut…$ xargs
Reconnaissance
1acad47b7703
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
9f95ddab5d15
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ whoami
Reconnaissance
428676f379db
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
2e4b6774c035
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uptime
Reconnaissance
54c4ee7566b1
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
03a5f14b8b3b
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
1cd306d21f5d
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -m 2>/dev/null || echo unknown
Reconnaissance
68f194c4b505
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ps aux | head -10
Reconnaissance
88ce4cf67027
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ netstat -tulpn | head -10
Reconnaissance
2248941e6d5e
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
39ade6c96ccf
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -m 2>/dev/null || echo unknown
Reconnaissance
d4e14b1574b0
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ps aux | head -10
Reconnaissance
d6a4933c0fe3
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -m 2>/dev/null || echo unknown
Reconnaissance
9eae19dfffae
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
88fe0db2c372
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
131f70c675a3
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
51e9c94c7e0e
LOGIN
2
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ nproc 2>/dev/null || (grep -c '^processor' /proc/cpuinfo 2>…$ grep -c ^processor /proc/cpuinfo 2 > /dev/null
Reconnaissance
e1d2b1edeceb
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ mount | head -5
Reconnaissance
fec23c8d7a66
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ history | tail -5
Reconnaissance
b3a5f6d1ceda
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
1d53c85ac8d1
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
8c9618ebaad7
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
bb5a48664a4e
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uptime
Reconnaissance
5e17bf849944
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
3c35949c4395
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -m 2>/dev/null || echo unknown
Reconnaissance
d8f33b61b53a
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
97e4974194c8
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
d136170e8c7d
LOGIN
2
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ nproc 2>/dev/null || (grep -c '^processor' /proc/cpuinfo 2>…$ grep -c ^processor /proc/cpuinfo 2 > /dev/null
Reconnaissance
91e9fa9c229f
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
610ffbd70ce5
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ls -la /
Reconnaissance
13260fc23c1e
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ ssh -V
Reconnaissance
cf979c539ee9
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uname -a
Reconnaissance
d13c7a581951
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname
Reconnaissance
366c1ce3725f
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ uptime
Reconnaissance
a725a3c39806
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ env | head -10
Reconnaissance
fd79d74556bb
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ pwd
Reconnaissance
58ce932f1b22
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ whoami
Reconnaissance
e2849f455de5
LOGIN
1
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ hostname