← Back to feed

172.214.47.55

TAGGED MALICIOUS how we decide →
Threat Confidence
55%
Location
🇺🇸 US / Washington
ASN
AS8075 · Microsoft Corporation
Cloud Provider
Microsoft Azure
Total Events
959
Top 5% by volume
Agent Count
1
First / Last Seen
2026-05-08 12:08 — 2026-05-08 15:07
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
malware_dropper ×53 credential_probe ×1
Sessions
54 (53 with login)
Avg Depth Score
0.99
Commands Executed
530
Files Downloaded
53
Notable Commands
  • echo "===HOSTNAME==="; hostname 2>/dev/null || echo EMPTY;; echo "===UNAME==="; uname -a 2>/dev/null || echo EMPTY;; echo "===WHOAMI==="; whoami 2>/dev/null || echo EMPTY;; echo "===PWD==="; pwd 2>/dev/null || echo EMPTY;; echo "===LS_ROOT==="; ls -la / 2>/dev/null | head -10 || echo EMPTY;; echo "===PS==="; ps aux 2>/dev/null | head -15 || echo EMPTY;; echo "===NETSTAT==="; netstat -tulpn 2>/dev/null | head -10 || echo EMPTY;; echo "===HISTORY==="; history 2>/dev/null | tail -5 || echo EMPTY;; echo "===SSH_VERSION==="; ssh -V 2>&1 || echo EMPTY;; echo "===UPTIME==="; uptime 2>/dev/null || echo EMPTY;; echo "===MOUNT==="; mount 2>/dev/null | head -5 || echo EMPTY;; echo "===ENV==="; env 2>/dev/null | head -10 || echo EMPTY;; echo "===CPU_CORES==="; nproc 2>/dev/null || grep -c '^processor' /proc/cpuinfo 2>/dev/null || echo 0;; echo "===ARCH==="; uname -m 2>/dev/null || echo unknown;; echo "===CPU_MODEL==="; grep 'model name' /proc/cpuinfo 2>/dev/null | head -1 | cut -d ':' -f2- | sed 's/^ *//' || echo unknown;; echo "===RESOURCES==="; echo MEMKB=$(awk '/MemTotal/{print $2}' /proc/meminfo 2>/dev/null) DISKKB=$(df / 2>/dev/null | awk 'NR==2{print $2}') USERCNT=$(wc -l < /etc/passwd 2>/dev/null) PKGCNT=$(dpkg -l 2>/dev/null | grep -c '^ii' || rpm -qa 2>/dev/null | wc -l || echo 0);; echo "===CONTAINER==="; cat /proc/1/cgroup 2>/dev/null | head -3; test -f /.dockerenv && echo DOCKERENV; test -f /run/.containerenv && echo CONTAINERENV; echo;; echo "===COWRIE==="; ls /opt/cowrie /home/richard /etc/cowrie 2>&1;; echo "===DMESG==="; dmesg 2>/dev/null | head -5 || echo EMPTY;; echo "===PORTS==="; ss -tulpn 2>/dev/null | grep LISTEN | head -20 || netstat -tulpn 2>/dev/null | grep LISTEN | head -20 || echo EMPTY;; echo "===NETCFG==="; ls -la /etc/network/interfaces /etc/sysconfig/network-scripts/ /etc/netplan/ 2>/dev/null | head -3 || echo EMPTY;; echo "===IPADDR==="; ip addr show 2>/dev/null | grep -E '^[0-9]+:' | head -5 || echo EMPTY;; echo "===IPROUTE==="; ip route show 2>/dev/null | head -3 || echo EMPTY;; echo "===WRITE==="; TF=/tmp/t_$$; echo test > $TF 2>&1 && echo WRITEOK && rm -f $TF || echo WRITEFAIL;; echo "===IDCHECK==="; id 2>/dev/null && echo IDOK || echo IDFAIL; whoami 2>/dev/null && echo WHOAMIOK || echo WHOAMIFAIL;; echo "===PKGMGR==="; which apt 2>/dev/null || which yum 2>/dev/null || which pacman 2>/dev/null || which zypper 2>/dev/null || echo NOPKG;; echo "===SERVICES==="; systemctl list-units --type=service --state=running 2>/dev/null | head -10 || echo NOSVC;; echo "===SOCKETS==="; ss -tuln 2>/dev/null | wc -l || echo 0;; echo "===GPU==="; nvidia-smi --query-gpu=name,memory.total,driver_version --format=csv,noheader 2>/dev/null || echo NOGPU;; echo "===MAXDISK==="; df -BG 2>/dev/null | awk 'NR>1{gsub("G","",$2); if($2+0>max) max=$2+0} END{print max+0}' || echo 0;; echo "===END==="
  • awk /MemTotal/{print $2} /proc/meminfo 2 > /dev/null
  • df / 2 > /dev/null | awk NR==2{print $2}
  • wc -l < /etc/passwd 2 > /dev/null
  • dpkg -l 2 > /dev/null | grep -c ^ii
  • rpm -qa 2 > /dev/null | wc -l
  • rpm -qa
  • echo 0
  • systemctl list-units --type=service --state=running
  • nvidia-smi --query-gpu=name,memory.total,driver_version --format=csv,noheader
Fingerprints
SSH-2.0-Go
Evidence Timeline
Malware Dropper 4d7d82c729ce newark_01 · 2026-05-08 15:07
10 1 1 100%
Loading events...
Malware Dropper 6739bc0a1f9b newark_01 · 2026-05-08 15:03
10 1 1 100%
Loading events...
Malware Dropper 682af159589a newark_01 · 2026-05-08 14:59
10 1 1 100%
Loading events...
Malware Dropper 3ac799f83988 newark_01 · 2026-05-08 14:58
10 1 1 100%
Loading events...
Malware Dropper 750fa719577c newark_01 · 2026-05-08 14:55
10 1 1 100%
Loading events...
Malware Dropper bd8afb47685e newark_01 · 2026-05-08 14:51
10 1 1 100%
Loading events...
Malware Dropper 428934f4f889 newark_01 · 2026-05-08 14:47
10 1 1 100%
Loading events...
Malware Dropper 9953649b593c newark_01 · 2026-05-08 14:43
10 1 1 100%
Loading events...
Malware Dropper c20892e995a3 newark_01 · 2026-05-08 14:42
10 1 1 100%
Loading events...
Malware Dropper 346e679437d1 newark_01 · 2026-05-08 14:39
10 1 1 100%
Loading events...
Malware Dropper bd06706506e0 newark_01 · 2026-05-08 14:35
10 1 1 100%
Loading events...
Malware Dropper bf9e0336c81b newark_01 · 2026-05-08 14:31
10 1 1 100%
Loading events...
Malware Dropper 38440dce27a6 newark_01 · 2026-05-08 14:28
10 1 1 100%
Loading events...
Malware Dropper 485ef7df8e1a newark_01 · 2026-05-08 14:27
10 1 1 100%
Loading events...
Malware Dropper f082cf867fcf newark_01 · 2026-05-08 14:19
10 1 1 100%
Loading events...
Malware Dropper 2de95f50e017 newark_01 · 2026-05-08 14:16
10 1 1 100%
Loading events...
Malware Dropper 06aead7893f4 newark_01 · 2026-05-08 14:12
10 1 1 100%
Loading events...
Malware Dropper 31f3dae1e55a newark_01 · 2026-05-08 14:11
10 1 1 100%
Loading events...
Malware Dropper 6de2ca3e20ec newark_01 · 2026-05-08 14:08
10 1 1 100%
Loading events...
Malware Dropper 2f072a701e5d newark_01 · 2026-05-08 14:04
10 1 1 100%
Loading events...
Malware Dropper f5581a3b35a3 newark_01 · 2026-05-08 13:56
10 1 1 100%
Loading events...
Malware Dropper 662c0d2b253f newark_01 · 2026-05-08 13:56
10 1 1 100%
Loading events...
Malware Dropper fd8d3dd36f45 newark_01 · 2026-05-08 13:52
10 1 1 100%
Loading events...
Malware Dropper 86a491dc107f newark_01 · 2026-05-08 13:48
10 1 1 100%
Loading events...
Malware Dropper ebc9e962adf2 newark_01 · 2026-05-08 13:44
10 1 1 100%
Loading events...
Malware Dropper a36480fe5232 newark_01 · 2026-05-08 13:40
10 1 1 100%
Loading events...
Malware Dropper 8488255bd810 newark_01 · 2026-05-08 13:40
10 1 1 100%
Loading events...
Malware Dropper 9c6f8ada9ca0 newark_01 · 2026-05-08 13:36
10 1 1 100%
Loading events...
Malware Dropper 156d7754fde6 newark_01 · 2026-05-08 13:33
10 1 1 100%
Loading events...
Malware Dropper 176e580ba833 newark_01 · 2026-05-08 13:29
10 1 1 100%
Loading events...
Malware Dropper 761a59fab97f newark_01 · 2026-05-08 13:25
10 1 1 100%
Loading events...
Malware Dropper f61639647f19 newark_01 · 2026-05-08 13:24
10 1 1 100%
Loading events...
Malware Dropper 8f10fa6a7072 newark_01 · 2026-05-08 13:21
10 1 1 100%
Loading events...
Malware Dropper a826d667f70e newark_01 · 2026-05-08 13:17
10 1 1 100%
Loading events...
Malware Dropper d6a847576bbe newark_01 · 2026-05-08 13:13
10 1 1 100%
Loading events...
Malware Dropper ed1709f20a60 newark_01 · 2026-05-08 13:10
10 1 1 100%
Loading events...
Malware Dropper 1c22b47a6759 newark_01 · 2026-05-08 13:09
10 1 1 100%
Loading events...
Malware Dropper c50f93902d2f newark_01 · 2026-05-08 13:05
10 1 1 100%
Loading events...
Malware Dropper e7efed3affc0 newark_01 · 2026-05-08 13:02
10 1 1 100%
Loading events...
Malware Dropper e712baf008f8 newark_01 · 2026-05-08 12:58
10 1 1 100%
Loading events...
Malware Dropper b22aa980346a newark_01 · 2026-05-08 12:54
10 1 1 100%
Loading events...
Malware Dropper caa3b32a078a newark_01 · 2026-05-08 12:53
10 1 1 100%
Loading events...
Malware Dropper 1888d6e2a857 newark_01 · 2026-05-08 12:50
10 1 1 100%
Loading events...
Malware Dropper 9d5abcb10528 newark_01 · 2026-05-08 12:46
10 1 1 100%
Loading events...
Malware Dropper f187e7daf74a newark_01 · 2026-05-08 12:42
10 1 1 100%
Loading events...
Malware Dropper 644ba0287f3c newark_01 · 2026-05-08 12:39
10 1 1 100%
Loading events...
Malware Dropper fc46a87cd083 newark_01 · 2026-05-08 12:38
10 1 1 100%
Loading events...
Malware Dropper a5e5dd97678b newark_01 · 2026-05-08 12:35
10 1 1 100%
Loading events...
Malware Dropper 6d6e97d8e071 newark_01 · 2026-05-08 12:31
10 1 1 100%
Loading events...
Malware Dropper 53c6a28a2c8d newark_01 · 2026-05-08 12:27
10 1 1 100%
Loading events...